Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.39%
Published
Aug 22, 2019
Modified
Nov 20, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
Weaknesses (CWE)
Affected Products (1)
References (2)