Lucene search

K
wpvulndbWpvulndbWPVDB-ID:07DA16E2-16BE-48EE-9BBC-9BBB526ACB0C
HistoryMar 22, 2024 - 12:00 a.m.

WP Media folder < 5.7.3 - Authenticated (Subscriber+) Arbitrary File Upload

2024-03-2200:00:00
wpscan.com
15
wordpress
media folder
plugin
vulnerability
authenticated
subscriber
arbitrary file upload

AI Score

7.7

Confidence

High

EPSS

0

Percentile

9.0%

Description The WP Media folder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site’s server which may make remote code execution possible.

AI Score

7.7

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:07DA16E2-16BE-48EE-9BBC-9BBB526ACB0C