WordPress Plugin Vulnerabilities

Envato Elements < 2.0.11 - Contributor+ Arbitrary File Upload

Description

The plugin does not properly check extracted uploaded archive files, allowing contributors and above roles to upload malicious templates containing PHP files

Affects Plugins

Fixed in 2.0.11

References

Miscellaneous

Original Researcher
Chloe Chamberland
Verified
No

Timeline

Publicly Published
2021-10-21 (about 4 years ago)
Added
2023-03-07 (about 3 years ago)
Last Updated
2023-03-07 (about 3 years ago)

Other