WordPress Plugin Vulnerabilities

Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Upload

Description

"A subscriber could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/themes/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site."

Proof of Concept

Affects Plugins

Fixed in 4.0.4
Fixed in 4.0.4

References

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2021-02-10 (about 4 years ago)
Added
2021-02-10 (about 4 years ago)
Last Updated
2021-04-07 (about 4 years ago)

Other