Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h635-5m37-x3p5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

EPSS

Процентиль: 100%
0.93119
Критический

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
почти 5 лет назад

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

EPSS

Процентиль: 100%
0.93119
Критический

Дефекты

CWE-434