WordPress AIT CSV Import/Export...

- AV AC AU C I A
发布: 2021-01-12
修订: 2024-12-11

WordPress AIT CSV Import/Export plugin versions 3.0.3 and below allow unauthenticated remote attackers to upload and execute arbitrary PHP code. The upload-handler does not require authentication, nor validates the uploaded content. It may return an error when attempting to parse a CSV, however the uploaded shell is left. The shell is uploaded to wp-content/uploads/. The plugin is not required to be activated to be exploitable.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息