Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-5414

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to other sites, for example in shared hosting environments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 83.0%
CVSS Severity
CVSS v3 Score 9.1
References
Products affected by CVE-2023-5414


Contact Us

Shodan ® - All rights reserved