PT-2022-9532 · WordPress · Wordpress File Upload Pro+1

Apple502J

·

Published

2022-03-28

·

Updated

2022-04-04

·

CVE-2021-24962

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress File Upload Free and Pro WordPress plugins versions prior to 4.16.3
Description The issue allows users with a role as low as Contributor to perform path traversal via a shortcode argument. This can be used to upload PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
Recommendations For WordPress File Upload Free and Pro WordPress plugins versions prior to 4.16.3, update to version 4.16.3 or later to resolve the issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24962

Affected Products

Wordpress File Upload Free
Wordpress File Upload Pro