ZeroHour

CVE-2021-24216

PoC
CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description

The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

Vendors
servmask
Products
one-stop wp migration
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.