CVE-2021-24962
28.03.2022, 18:15
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
Vendor | Product | Version |
---|---|---|
iptanus | wordpress_file_upload | 𝑥 < 4.16.3 |
iptanus | wordpress_file_upload_pro | 𝑥 < 4.16.3 |
𝑥
= Vulnerable software versions