WordPress Plugin Vulnerabilities

Motors - Car Dealer, Classifieds & Listing < 1.4.4 - Arbitrary File Upload

Description

The plugin does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
cydave
Submitter
cydave
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-11-21 (about 3 years ago)
Added
2022-11-21 (about 3 years ago)
Last Updated
2022-12-08 (about 3 years ago)

Other