Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jm79-ggg6-34q9

Опубликовано: 03 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.

EPSS

Процентиль: 54%
0.00754
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.

EPSS

Процентиль: 54%
0.00754
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434