CVE-2023-0039
CVSS V2 None
CVSS V3 None
Description
** REJECT ** Duplicate. Please use CVE-2022-4060 instead.
Overview
- CVE ID
- CVE-2023-0039
- Assigner
- security@wordfence.com
- Vulnerability Status
- Rejected
- Published Version
- 2023-01-03T15:15:10
- Last Modified Date
- 2023-04-12T21:15:13
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:odude:user_post_gallery:*:*:*:*:*:wordpress:*:* | 1 | OR | 2.19 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-0039 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0039 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-01-03 16:16:59 | Added to TrackCVE | |||
2023-01-03 16:17:00 | Weakness Enumeration | new | ||
2023-01-09 12:21:24 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2023-01-10 14:18:23 | 2023-01-10T13:50:17 | CVE Modified Date | updated | |
2023-01-10 14:18:23 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-01-10 14:18:25 | CPE Information | updated | ||
2023-04-12 22:19:23 | 2023-04-12T21:15:13 | CVE Modified Date | updated | |
2023-04-12 22:19:23 | Analyzed | Rejected | Vulnerability Status | updated |
2023-04-12 22:19:23 | The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command execution due to the use of a nopriv AJAX action and user supplied function calls and parameters in versions up to, and including 2.19. This makes it possible for unauthenticated attackers to call arbitrary PHP functions and perform actions like adding new files that can be webshells and updating the site's options to allow anyone to register as an administrator. | ** REJECT ** Duplicate. Please use CVE-2022-4060 instead. | Description | updated |