The plugin allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
As any authenticated user, upload a PHP file via /wp-admin/upload.php?page=adv-file-upload The file will be at https://example.com/wp-content/uploads/2022/03/<filename>.php
UPLOAD
Roel van Beurden
Roel van Beurden
Yes
2022-04-19 (about 11 months ago)
2022-04-19 (about 11 months ago)
2022-04-20 (about 11 months ago)