Логотип exploitDog
bind:CVE-2022-3989
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3989

Количество 2

Количество 2

nvd логотип

CVE-2022-3989

около 3 лет назад

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v968-jc69-vxr8

около 3 лет назад

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3989

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-v968-jc69-vxr8

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

CVSS3: 8.8
1%
Низкий
около 3 лет назад

Уязвимостей на страницу