WordPress Plugin Vulnerabilities

Download Manager < 3.1.19 - Authenticated (author+) PHP4 File Upload to RCE

Description

The wpdm_admin_upload_file AJAX action used a blacklist approach to forbid potential dangerous files, such as PHP, from being uploaded. However, other dangerous extensions, like .php4 were not forbidden.

Proof of Concept

Affects Plugins

Fixed in 3.1.19

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-04-30 (about 4 years ago)
Added
2021-04-30 (about 4 years ago)
Last Updated
2021-04-30 (about 4 years ago)

Other