High severity7.2NVD Advisory· Published May 2, 2023· Updated Jun 17, 2026
CVE-2023-0924
CVE-2023-0924
Description
The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/ZYREX POPUPdescription
- Range: <=1.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/0fd0d7a5-9263-43b6-9244-7880c3d3e6f4nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.