Showing 1 vulnerability on this page for business_hours_pro

Signals CISA KEV Ransomware Nuclei
AivahThemes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCE

The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.

CWE-434Apr 22, 2021
CVSS9.8v3.1EPSS3.04%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX