Unrestricted File Upload Vulnerability in Baggage Freight Shipping Plugin for WordPress
⚠️ CVE-Referenzen:
CVE-2018-25436
WordPress - Baggage Freight Shipping Australia - CRITICAL - CVE-2018-25436.
The Baggage Freight Shipping Plugin for WordPress version 0.1.0 is susceptible to an arbitrary file upload vulnerability caused by inadequate validation of uploaded files through the upload-package.php endpoint. This flaw permits unauthenticated attackers to remotely upload malicious files to the server. By sending specially crafted POST requests, attackers can exploit this vulnerability to execute arbitrary code, potentially compromising the entire WordPress installation.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io