WordPress Plugin Vulnerabilities
Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Upload
Description
"A subscriber could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/themes/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site."
Proof of Concept
Affects Plugins
References
Miscellaneous
Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2021-02-10 (about 4 years ago)
Added
2021-02-10 (about 4 years ago)
Last Updated
2021-04-07 (about 4 years ago)