← back
CVE-2023-4019high

Media from FTP < 11.17 - Author+ Arbitrary File Access

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.7%
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Media from FTP