High severity7.2NVD Advisory· Published Feb 5, 2024· Updated Apr 8, 2026
CVE-2023-6635
CVE-2023-6635
Description
The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'import_styles' function in versions up to, and including, 1.40.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:extendify:editorskit:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:extendify:editorskit:*:*:*:*:*:wordpress:*:*range: <=1.40.3
- (no CPE)range: <=1.40.3
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/3010794/block-optionsnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/4528f9a1-7027-4aa9-b006-bea84aa19c84nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/block-options/tags/1.40.3/includes/addons/styles-manager/rest-api/gutenberghub-styles-import-export-controller.phpnvdIssue Tracking
News mentions
0No linked articles in our index yet.