The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/8f982ebd-6fc5-452d-8280-42e027d01b1e | Exploit Third Party Advisory |
Configurations
Information
Published : 2023-01-16 08:15
Updated : 2023-01-24 10:23
NVD link : CVE-2022-4060
Mitre link : CVE-2022-4060
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
odude
- user_post_gallery