vendor:
PicUploader
by:
Milad Karimi
7.5
CVSS
HIGH
Remote File Upload
CWE
Product Name: PicUploader
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10, Firefox
2020
WordPress Plugin PicUploader 1.0 – Remote File Upload
The PicUploader plugin for Wordpress version 1.0 allows remote attackers to upload arbitrary files to the server due to improper handling of file uploads. This can lead to remote code execution or unauthorized access to sensitive information.
Mitigation:
The vendor has not provided a fix or mitigation for this vulnerability. It is recommended to remove the PicUploader plugin from the Wordpress installation or use an alternative plugin with proper file upload handling.