WordPress Plugin Vulnerabilities
All-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE
Description
The plugin does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.
Proof of Concept
Affects Plugins
References
Miscellaneous
Original Researcher
YICHENG LIU-ZTE CHENFENG lab
Submitter
YICHENG LIU_chenfeng lab
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-02-07 (about 3 years ago)
Added
2022-02-07 (about 3 years ago)
Last Updated
2022-04-13 (about 3 years ago)