The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-08T19:00:32.181Z
Updated: 2025-06-18T16:04:16.427Z
Reserved: 2023-11-03T17:40:53.323Z
Link: CVE-2023-5957

Updated: 2024-08-02T08:14:25.192Z

Status : Modified
Published: 2024-01-08T19:15:09.890
Modified: 2025-06-18T16:15:24.493
Link: CVE-2023-5957

No data.