vendor:
WP Add Mime Types Plugin
by:
Princy Edward
7.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: WP Add Mime Types Plugin
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: YES
Related CWE: Fresh
CPE: a:wordpress:wp_add_mime_types
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Apache/2.2.24 (CentOS)
2019
CSRF vulnerabilities in WP Add Mime Types Plugin <= 2.2.1
WordPress plugin WP Add Mime Types plugin 2.2.1 is vulnerable to CWE-352. A malicious link can be shared to the plugin user which, once clicked, will automatically update the mime type. A POC is shared to allow exe files (application/x-msdownload) to be uploaded.
Mitigation:
The plugin should be updated to the latest version to fix the vulnerability.