← Back to browse · API

CVE-2023-5199

Severity
CRITICAL
CVSS
9.9
EPSS
0.01383
Risk score
40.08
CISA KEV
No
PoC
No
Published
2023-10-30
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2023-57530, GHSA-PWFP-GQPX-2MGG
Products
bloafer:PHP to Page 0 ≤0.3
Sources
euvd EUVD-2023-57530

Description

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.

References