Lucene search

K
wpvulndbRaad Haddad of Cloudyrion GmbHWPVDB-ID:7DB363BF-7BEF-4D47-9963-C30D6FDD2FB8
HistorySep 26, 2022 - 12:00 a.m.

Frontend File Manager < 21.4 - File Upload via CSRF

2022-09-2600:00:00
Raad Haddad of Cloudyrion GmbH
wpscan.com
10
file manager
csrf
file upload
security vulnerability
attack vector
wordpress

EPSS

0.001

Percentile

25.9%

The plugin does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

PoC

The file won’t show up via the frontend/backend, but will be uploaded in the user folder (ie in wp-content/uploads/user_uploads//payload.pdf)

EPSS

0.001

Percentile

25.9%

Related for WPVDB-ID:7DB363BF-7BEF-4D47-9963-C30D6FDD2FB8