Lucene search

K
wpvulndbWpvulndbWPVDB-ID:1E56E2B0-C494-4971-85E8-75C776DB2797
HistoryAug 11, 2022 - 12:00 a.m.

Uploading SVG, WEBP and ICO files <= 1.0.1 - Admin+ Arbitrary File Upload

2022-08-1100:00:00
wpscan.com
6
svg
webp
ico
admin
arbitrary file upload
privilege escalation

0.001 Low

EPSS

Percentile

42.8%

The plugin does not validate the files to be uploaded, which could allow high privilege users such as admin to upload arbitrary files, even when they are not supposed to

CPENameOperatorVersion
uploading-svgwebp-and-ico-fileseq*

0.001 Low

EPSS

Percentile

42.8%

Related for WPVDB-ID:1E56E2B0-C494-4971-85E8-75C776DB2797