WordPress Plugin Vulnerabilities
PostmagThemes Demo < 1.0.8 - Admin+ Arbitrary File Upload
Description
The plugin does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
thunder.god.hhh@gmail.com
Submitter
thunder.god.hhh@gmail.com
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-11-11 (about 3 years ago)
Added
2022-11-11 (about 3 years ago)
Last Updated
2022-12-21 (about 3 years ago)