CVE-2023-51417 CRITICAL

CVE-2023-51417: WordPress JVM rich text icons Plugin <= 1.2.3 is vulnerable to Arbitrary File Upload

Vendor Joris Van Montfort
Product JVM Gutenberg Rich Text Icons
Weakness CWE-434 · Unrestricted file upload
Published December 29, 2023
Last update April 28, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3.

Explanation of Vulnerability in Simple Terms

02Summary

JVM Gutenberg Rich Text Icons allows authenticated users to upload files without proper validation. An attacker with low-level site access can upload malicious files that execute code on the server, potentially compromising the entire site. The vulnerability affects all versions up to 1.2.3.

What an attacker can do

03Attacker Capabilities

Upload and execute malicious files on the server, gaining full control of the site.

Potential impact on your site

04Site Impact

Any user with upload permissions can compromise your site; immediate patching required to prevent takeover.

Conditions required to exploit

05Prerequisites

Attacker needs a low-privilege user account (e.g., contributor or editor role) on the site.

Key dates

06Disclosure timeline

December 29, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE