vendor:
Zen App Mobile Native, webapp-builder, wp2android-turn-wp-site-into-android-app, mobile-app-builder-by-wappress, mobile-friendly-app-builder-by-easytouch
by:
Larry W. Cashdollar and Munir Njiru
9,8
CVSS
CRITICAL
Remote File Upload
434
CWE
Product Name: Zen App Mobile Native, webapp-builder, wp2android-turn-wp-site-into-android-app, mobile-app-builder-by-wappress, mobile-friendly-app-builder-by-easytouch
Affected Version From: 3.0
Affected Version To: 1.05
Patch Exists: YES
Related CWE: CVE-2017-6104, CVE-2017-1002002, CVE-2017-1002003, CVE-2017-1002001, CVE-2017-1002000
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Wordpress
2017
Multiple WordPress Plugin – Remote File Upload Exploit
Multiple Wordpress plugins are vulnerable to a remote file upload vulnerability. This vulnerability allows an attacker to upload a malicious file to the vulnerable server. The vulnerable plugins are Zen App Mobile Native <=3.0 (CVE-2017-6104), Wordpress Plugin webapp-builder v2.0 (CVE-2017-1002002), Wordpress Plugin wp2android-turn-wp-site-into-android-app v1.1.4 (CVE-2017-1002003), Wordpress Plugin mobile-app-builder-by-wappress v1.05 (CVE-2017-1002001), and Wordpress Plugin mobile-friendly-app-builder-by-easytouch v3.0 (CVE-2017-1002000).
Mitigation:
Ensure that all plugins are up to date and that only trusted plugins are installed on the server.