CVE Database
/

CVE-2023-4019

Back to search

CVE-2023-4019

Published: Sep 4, 2023

Modified: Apr 23, 2025

PUBLISHED

Description

The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases.

VendorProductVersions

Unknown

Media from FTP

affected
0 - < 11.17

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now