WordPress Plugin Vulnerabilities

Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload

Description

The plugin allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

Proof of Concept

As any authenticated user, upload a PHP file via /wp-admin/upload.php?page=adv-file-upload

The file will be at https://example.com/wp-content/uploads/2022/03/<filename>.php

Affects Plugins

No known fix

References

Miscellaneous

Original Researcher
Roel van Beurden
Submitter
Roel van Beurden
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-04-19 (about 2 years ago)
Added
2022-04-19 (about 2 years ago)
Last Updated
2022-04-20 (about 2 years ago)

Other