ZeroHour

CVE-2022-1103

PoC
CVSS 3.1
8.8 high
EPSS
16%p97
Published
()
Modified
Description

The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

Vendors
advanced uploader project
Products
advanced uploader
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.