Lucene search

K
wpvulndbWpvulndbWPVDB-ID:1B841A64-FB0A-434F-B7B4-0777F0480C87
HistoryNov 23, 2023 - 12:00 a.m.

Slider Revolution < 6.6.16 - Authenticated (Author+) Arbitrary File Upload

2023-11-2300:00:00
wpscan.com
57
wordpress
slider revolution
arbitrary file upload
remote code execution
security vulnerability

AI Score

8.1

Confidence

Low

EPSS

0.001

Percentile

19.3%

Description The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 6.6.15. This makes it possible for attackers with author-level access and higher to upload arbitrary files on the affected site’s server which may make remote code execution possible.

AI Score

8.1

Confidence

Low

EPSS

0.001

Percentile

19.3%

Related for WPVDB-ID:1B841A64-FB0A-434F-B7B4-0777F0480C87