CVE-2023-0080

CVE-2023-0080: Customer Reviews for WooCommerce < 5.16.0 - Contributor+ LFI

Vendor Unknown
Product Customer Reviews for WooCommerce
Published February 13, 2023
Last update March 21, 2025

CVSS base score

What the vulnerability does

01Description

The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

Key dates

02Disclosure timeline

February 13, 2023 CVE published
March 21, 2025 Record updated