WordPress Plugin Vulnerabilities

Super Forms < 4.9.703 - Unauthenticated PHP File Upload to RCE

Description

The plugin uses the jQuery File Upload library, but does not properly ensure that PHP files are forbidden.

Note: Exploitation of the issue is not as easy as the original advisory (in the references) states.

Proof of Concept

Affects Plugins

Fixed in 4.9.703
Fixed in 4.9.703

References

Exploitdb

Miscellaneous

Original Researcher
ABDO10
Verified
Yes

Timeline

Publicly Published
2021-01-28 (about 5 years ago)
Added
2021-01-28 (about 5 years ago)
Last Updated
2021-02-01 (about 5 years ago)

Other