Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv5c-hx24-mwv4

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

EPSS

Процентиль: 28%
0.00347
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

EPSS

Процентиль: 28%
0.00347
Низкий

7.2 High

CVSS3

Дефекты

CWE-434