Описание
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.6.2 (исключая)
cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 45%
0.00223
Низкий
7.5 High
CVSS3
5.1 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
github
около 4 лет назад
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
EPSS
Процентиль: 45%
0.00223
Низкий
7.5 High
CVSS3
5.1 Medium
CVSS2
Дефекты
CWE-352