CVE-2023-5601

CVE-2023-5601: WooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File Upload

Vendor Unknown
Product WooCommerce Ninja Forms Product Add-ons
Published November 6, 2023
Last update March 25, 2025

CVSS base score

What the vulnerability does

01Description

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

Key dates

02Disclosure timeline

November 6, 2023 CVE published
March 25, 2025 Record updated