ZeroHour

CVE-2022-4061

PoC
CVSS 3.1
7.5 high
EPSS
1%p70
Published
()
Modified
Description

The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.

Vendors
ultimatemember
Products
jobboardwp
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.