Critical CVSS: CRITICAL CVE-2023-5414 vulnerability

CVE-2023-5414: The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in

Tracked since May 6, 2026 View on NVD

CVSS Breakdown

9.1
CVSS Base Score
CRITICAL
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A

Insurance Impact Assessment

🛡️
Critical Impact

Critical vulnerabilities require urgent remediation. Insurers may impose coverage conditions, increased retentions, or exclusion endorsements until patches are applied.

CVE CVE-2023-5414 with CVSS 9.1. The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including tho

View on NVD

Assess your exposure

Is your organization vulnerable? Run a free domain exposure scan to check.

← Back to Threat Feed