E2Pdf <= 1.20.25 - Authenticated (Administrator+) Arbitrary File Upload

2023-12-13 00:00
István Márton

Strategic Overview

Status
Patched in 1.20.26
Affected Version<= 1.20.25
CVSS7.2High
CVECVE-2023-6826
View all E2Pdf – Export Pdf Tool for WordPress vulnerabilities

Vulnerability Overview

The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Technical Analysis

REMEDIATION: Update to version 1.20.26, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C