HIGH

CVE-2023-4238

CVSS v3

7.2

HIGH

EPSS Score

22.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

Technical details

Published
9/25/2023

Frequently asked questions

What is CVE-2023-4238?

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

Is CVE-2023-4238 actively exploited?

Active exploitation of CVE-2023-4238 has not been confirmed. The EPSS score is 22.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-4238?

CVE-2023-4238 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2023-4238 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.