Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3gc-6887-36p6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.

Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.

EPSS

Процентиль: 96%
0.24503
Средний

Связанные уязвимости

nvd
около 13 лет назад

Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.

EPSS

Процентиль: 96%
0.24503
Средний