plugin

Php To Page Vulnerabilities

1 known security issue reported for the Php To Page WordPress plugin. Most recent disclosed Oct 29, 2023.

1 critical

Running Php To Page on your site? Check whether your installed version is affected.

Scan your site free

PHP to Page <= 0.3 - Authenticated (Subscriber+) Local File Inclusion to Remote Code Execution via Shortcode

critical

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While...

CVSS:
9.9
Affected:
up to 0.3
Fix:
No patched version reported
Disclosed:
Oct 29, 2023

CVE-2023-5199 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database