Описание
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party uploadify.php script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
Ссылки
EPSS
Процентиль: 99%
0.73719
Высокий
Дефекты
CWE-434
Связанные уязвимости
github
6 месяцев назад
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
EPSS
Процентиль: 99%
0.73719
Высокий
Дефекты
CWE-434