WordPress Vulnerabilities
WordPress < 6.4.3 - Admin+ PHP File Upload
Description
WordPress allows high privileged users (Admin / Super Admin on Mulsitite) to upload PHP files directly via the plugin/theme upload feature.
Note: Such issue is only a concern on hardened blogs where such users are not allowed to install plugins/themes.
Affects WordPress
References
Miscellaneous
Original Researcher
m4tuto
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-01-30 (about 1 year ago)
Added
2024-01-30 (about 1 year ago)
Last Updated
2024-01-30 (about 1 year ago)