vendor:
3DPrint Lite
by:
spacehen
8,8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: 3DPrint Lite
Affected Version From: 1.9.1.4
Affected Version To: 1.9.1.4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 20.04.1
2021
WordPress Plugin 3DPrint Lite 1.9.1.4 – Arbitrary File Upload
This exploit allows an attacker to upload a malicious file to the vulnerable Wordpress Plugin 3DPrint Lite version 1.9.1.4. The attacker can upload a malicious file to the vulnerable plugin by sending a POST request to the admin-ajax.php page with the action parameter set to p3dlite_handle_upload. The malicious file will be uploaded to the wp-content/uploads/p3d/ directory.
Mitigation:
Update to the latest version of the plugin or disable the plugin if it is not needed.