Описание
The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.17 (исключая)
cpe:2.3:a:riverforest-wp:media_from_ftp:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 48%
0.0025
Низкий
8.8 High
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 8.8
github
больше 2 лет назад
The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases.
EPSS
Процентиль: 48%
0.0025
Низкий
8.8 High
CVSS3