WordPress Plugin Vulnerabilities

Royal Elementor Addons and Templates 1.4.78 - Unauthenticated Arbitrary File Upload

Description

The plugin does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Note that this vulnerability is identical to https://wpscan.com/vulnerability/281518ff-7816-4007-b712-63aed7828b34/ as it was introduced in the `1.4.x` branch in error.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Fioravante Souza
Submitter
Fioravante Souza
Verified
Yes

Timeline

Publicly Published
2023-10-09 (about 2 years ago)
Added
2023-10-23 (about 2 years ago)
Last Updated
2024-10-18 (about 1 year ago)

Other