The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/4d7b62e1-558b-4504-a6e2-78246a8b554f | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-06-20 04:15
Updated : 2022-06-28 11:30
NVD link : CVE-2022-1939
Mitre link : CVE-2022-1939
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
allow_svg_files_project
- allow_svg_files