vendor:
Beauty Premium Theme
by:
Colette Chamberland (Wordfence)
7,5
CVSS
HIGH
CSRF and File Upload Vulnerability
264
CWE
Product Name: Beauty Premium Theme
Affected Version From: 1.0.8
Affected Version To: 1.0.8
Patch Exists: YES
Related CWE: N/A
CPE: a:yourinspirationweb:beauty_premium_theme
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Wordpress 4.2.x-4.4.x
2016
WordPress Beauty Theme File Upload Vulnerability v1.0.8
The Beauty Premium theme contains a contact form that is vulnerable to CSRF and File Upload vulnerability in the sendmail.php file. The file attachment gets uploaded to the wordpress upload directory and it is not sanitized, allowing attackers to upload harmful code.
Mitigation:
Ensure that all file uploads are properly sanitized and validated before being accepted.