HomeDefault status
affected
Any version
affected
Description
The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/673f35ff-e1d5-4099-86e7-8b6e3e410ef8/