Back to search
CVE-2021-24962
Published: Mar 28, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
| Vendor | Product | Versions |
|---|---|---|
Unknown | WordPress File Upload | affected 4.16.3 - < 4.16.3 |
Unknown | WordPress File Upload Pro | affected 4.16.3 - < 4.16.3 |
Weaknesses (CWE)
References
https://plugins.trac.wordpress.org/changeset/2677722
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now