WordPress Plugin Vulnerabilities

Amelia < 1.0.46 - Manager+ RCE

Description

The plugin stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

Proof of Concept

Affects Plugins

Fixed in 1.0.46

References

Miscellaneous

Original Researcher
qerogram
Submitter
qerogram
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-02-23 (about 3 years ago)
Added
2022-02-23 (about 3 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other