vendor:
Advanced Uploader
by:
Roel van Beurden
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Advanced Uploader
Affected Version From: <=4.2
Affected Version To: <=4.2
Patch Exists: YES
Related CWE: CVE-2022-1103
CPE: a:wordpress:advanced_uploader
Platforms Tested: WordPress 5.9 on Ubuntu 18.04
2022
WordPress Plugin Advanced Uploader 4.2 – Arbitrary File Upload (Authenticated)
WordPress Plugin Advanced Uploader <=4.2 allows authenticated arbitrary file upload. Any file(type) can be uploaded. A malicious user can perform remote code execution on the backend webserver.
Mitigation:
Ensure that the Advanced Uploader plugin is up to date and that all users are authenticated before allowing them to upload files.