Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7h3-h25c-vhc5

Опубликовано: 18 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.

EPSS

Процентиль: 12%
0.00215
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.

EPSS

Процентиль: 12%
0.00215
Низкий

6.5 Medium

CVSS3