Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Net-Hunter

#30009of 53,622
8.8Total CVSS
Vulnerabilities · 1
PT-2026-41427
8.8
2026-05-16
WordPress · Hs Brand Logo Slider · CVE-2020-37227
**Name of the Vulnerable Software and Affected Versions** HS Brand Logo Slider version 2.1 **Description** An unrestricted file upload flaw allows authenticated users to bypass client-side file extension validation. By intercepting upload requests to the `logoupload` parameter within the admin interface, attackers can upload arbitrary files with executable extensions such as .php to achieve remote code execution (the ability to execute arbitrary commands on the host server). **Recommendations** Restrict access to the `logoupload` parameter in the admin interface as a temporary mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.