AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-0924

HIGH · CVSS 7.2 EPSS 0.96%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-05-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-0924
Severity
HIGH
CVSS
7.2
EPSS
0.96%
WordPress

Original NVD Description

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.