Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3B7E04DE-E23F-4CF9-A9BF-2CF4CBC8C538
HistoryJan 14, 2020 - 12:00 a.m.

Elementor < 2.7.5 - Authenticated Arbitrary File Upload

2020-01-1400:00:00
wpscan.com
18

EPSS

0.001

Percentile

49.1%

The Elementor plugin (version 2.7.4 and below) was found to be vulnerable to an arbitrary file upload. Due to the application not handling zip files with directories properly an attacker could upload php files which were executable, this allowed any user able to import templates (WordPress role β€œContributor” or above) to execute commands on the underlying server.

EPSS

0.001

Percentile

49.1%

Related for WPVDB-ID:3B7E04DE-E23F-4CF9-A9BF-2CF4CBC8C538