PT-2022-9532 · WordPress · Wordpress File Upload Pro+1
Apple502J
·
Published
2022-03-28
·
Updated
2022-04-04
·
CVE-2021-24962
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress File Upload Free and Pro WordPress plugins versions prior to 4.16.3
Description
The issue allows users with a role as low as Contributor to perform path traversal via a shortcode argument. This can be used to upload PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
Recommendations
For WordPress File Upload Free and Pro WordPress plugins versions prior to 4.16.3, update to version 4.16.3 or later to resolve the issue.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress File Upload Free
Wordpress File Upload Pro