AkashLingayat

1 exploit Active since Apr 2021
CVE-2020-35314 NOMISEC CRITICAL WORKING POC
WonderCMS 3.1.3 - Authenticated Remote Code Execution via Theme/Plugin Installer
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.
CVSS 9.8