vendor:
WordPress Plugin SuperForms
by:
ABDO10
7.5
CVSS
HIGH
Arbitrary File Upload to Remote Code Execution
Not specified
CWE
Product Name: WordPress Plugin SuperForms
Affected Version From: All versions up to and including 4.9.X
Affected Version To: 4.9.X
Patch Exists: NO
Related CWE: Not specified
CPE: Not specified
Platforms Tested:
2021
WordPress Plugin SuperForms 4.9 – Arbitrary File Upload to Remote Code Execution
The WordPress Plugin SuperForms version 4.9 allows arbitrary file upload, leading to remote code execution. An attacker can upload a malicious file with a .php4 extension to execute arbitrary code on the server. The file can be found in the /wp-content/uploads/superforms/2021/01/<id>/filename.php4 directory, where <id> can be obtained from the server reply.
Mitigation:
Update to a version higher than 4.9.X to fix the vulnerability. Remove any unnecessary or unused plugins.