Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv6m-g863-2r99

Опубликовано: 13 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

EPSS

Процентиль: 61%
0.00419
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

EPSS

Процентиль: 61%
0.00419
Низкий

8.8 High

CVSS3

Дефекты

CWE-434