WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files in the file_manager directory and execute them on the server.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 08 Jun 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files in the file_manager directory and execute them on the server. | |
| Title | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated | |
| First Time appeared |
Webandprint
Webandprint ar |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:webandprint:ar:7.0:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webandprint
Webandprint ar |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-08T01:55:28.450Z
Reserved: 2026-01-10T01:51:52.987Z
Link: CVE-2023-54350
No data.
Status : Received
Published: 2026-06-08T02:16:22.810
Modified: 2026-06-08T02:16:22.810
Link: CVE-2023-54350
No data.
OpenCVE Enrichment
Updated: 2026-06-08T03:30:16Z
Weaknesses