CVE · Critical

CVE-2023-47873 — WP Child Theme Generator [wp-child-theme-generator] < 1.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-47873 WP Child Theme Generator [wp-child-theme-generator] < 1.1.3 Unrestricted Upload of File with Dangerous Type Critical 9.1 < 1.1.3 1.1.3 2023-11-20

CVE-2023-47873

The WP Child Theme Generator plugin before version 1.1.3 contains an arbitrary file upload vulnerability that allows attackers to upload files of any type to an affected website. These uploaded files could include malicious code such as backdoors that execute upon upload, potentially providing attackers with unauthorized access and control over the website. As of the advisory date, no patched version addressing this flaw had been released.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.