vendor:
WP User Frontend
by:
Panagiotis Vagenas
7,5
CVSS
HIGH
Unrestricted File Upload
264
CWE
Product Name: WP User Frontend
Affected Version From: < 2.3.11
Affected Version To: < 2.3.11
Patch Exists: YES
Related CWE: N/A
CPE: a:wedevs:wp_user_frontend
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress 4.4.2
2016
WordPress WP User Frontend Plugin [Unrestricted File Upload]
WordPress plugin WP User Frontend suffers from an unrestricted file uploade vulnerability. An attacker can exploit the wpuf_file_upload or wpuf_insert_image actions to upload any file which pass the WordPress mime and size checks. The attack does not require any privilege to be performed. The mentioned actions are available to non-privileged users also, thus allowing to anyone uploading files to the web server.
Mitigation:
Vendor implemented security checks and released v2.3.11 which resolves this issue.