WordPress Plugin Vulnerabilities

All-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE

Description

The plugin does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
YICHENG LIU-ZTE CHENFENG lab
Submitter
YICHENG LIU_chenfeng lab
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-02-07 (about 3 years ago)
Added
2022-02-07 (about 3 years ago)
Last Updated
2022-04-13 (about 3 years ago)

Other