Description
The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the 'addLibraryByArchive' function in all versions up to, and including, 4.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.
Problem types
Product status
* (semver)
Timeline
| 2025-01-08: | Disclosed |
Credits
Matthew Rollings
Youcef Hamdani
References
www.wordfence.com/...-c1aa-4df7-a9f9-1ca5837643e1?source=cve
plugins.trac.wordpress.org/...t-builder/trunk/sktbuilder.php
plugins.trac.wordpress.org/...-builder&sfp_email=&sfph_mail=
plugins.trac.wordpress.org/...-builder&sfp_email=&sfph_mail=