Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yichengliu

Researcher fromchenfeng lab
#38619of 53,632
7.2Total CVSS
Vulnerabilities · 1
PT-2022-9438
7.2
2022-03-07
WordPress · All-In-One Wp Migration · CVE-2021-24216
**Name of the Vulnerable Software and Affected Versions** All-in-One WP Migration WordPress plugin versions prior to 7.41 **Description** The issue allows administrators to upload PHP files on their site due to a lack of validation of uploaded files' extensions. This affects even multisite installations. **Recommendations** For versions prior to 7.41, update to version 7.41 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to trusted users or disabling the file upload feature until the update is applied.