CVE Database /
CVE-2023-6635
CVE · High
CVE-2023-6635 — Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.40.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6635
|
Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.40.4 |
Unrestricted Upload of File with Dangerous Type |
High
7.2
|
< 1.40.4
|
1.40.4 |
2023-12-16 |
—
|
CVE-2023-6635
A file upload vulnerability was discovered in the EditorsKit plugin for WordPress that could allow an attacker to upload arbitrary files to a website, potentially including malicious backdoors that could be executed to compromise the site. The flaw affects versions before 1.40.4 and was discovered by István Márton. Users should update to version 1.40.4 or later to remediate the issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings