Showing 1 vulnerability on this page for external_media

Signals CISA KEV Ransomware Nuclei
external_media_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

External Media < 1.0.34 - Authenticated Arbitrary File Upload

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.

CWE-285CWE-434Jun 1, 2021
CVSS8.8v3.1EPSS1.78%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX