Логотип exploitDog
bind:CVE-2023-0477
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-0477

Количество 2

Количество 2

nvd логотип

CVE-2023-0477

почти 3 года назад

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv6m-g863-2r99

почти 3 года назад

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-0477

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xv6m-g863-2r99

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

CVSS3: 8.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу