plugin

Jvm Rich Text Icons Vulnerabilities

2 known security issues reported for the Jvm Rich Text Icons WordPress plugin. Most recent disclosed Dec 27, 2023.

2 high

Running Jvm Rich Text Icons on your site? Check whether your installed version is affected.

Scan your site free

JVM rich text icons <= 1.2.6 - Directory Traversal to Authenticated(Subscriber+) Arbitrary File Deletion

high

The JVM Gutenberg Rich Text Icons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the 'file' parameter. This makes it possible for authenticated attackers, with subscriber access and above, to delete arbitrary files.

CVSS:
8.8
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Dec 27, 2023

CVE-2023-51418 on NVD →

JVM rich text icons <= 1.2.3 - Authenticated(Subscriber+) Arbitrary File Upload

high

The JVM Gutenberg Rich Text Icons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload_icon' function in all versions up to and including 1.2.3. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitrary files...

CVSS:
8.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Dec 27, 2023

CVE-2023-51417 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database