CVE-2023-31215 describes an Unrestricted Upload of File with Dangerous Type vulnerability affecting AmaderCode Lab Dropshipping & Affiliation with Amazon versions up to and including 2.1.2. This flaw allows an authenticated attacker to upload malicious files, potentially leading to remote code execution or system compromise. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low privileges and no user interaction, posing a significant risk of high impact to confidentiality, integrity, and availability. The EPSS score is low, indicating a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules for Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.2CPE matchmatch criteria | cpe:2.3:a:amadercode:dropshipping_\&_affiliation_with_amazon:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.