vendor:
Adning Advertising
by:
spacehen
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Adning Advertising
Affected Version From: 1.5.5
Affected Version To: 1.5.6
Patch Exists: YES
Related CWE: N/A
CPE: a:adning:adning_advertising
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 20.04.1 LTS (x86)
2020
WordPress Plugin Adning Advertising 1.5.5 – Arbitrary File Upload
This exploit allows an attacker to upload a malicious PHP file to the vulnerable WordPress plugin Adning Advertising 1.5.5. The attacker can then execute the malicious file by accessing it directly from the server. This vulnerability is due to the lack of proper input validation and authentication checks in the plugin.
Mitigation:
Upgrade to version 1.5.6 or later of the Adning Advertising plugin.