CVE-2016-20075
HIGHWordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20075. PoCs published by i0akiN SEC-LABORATORY.
AI-analyzed exploit summary This is a technical writeup detailing an arbitrary file upload vulnerability in WordPress Ultimate Product Catalogue Plugin v3.8.6. The vulnerability allows authenticated users to upload malicious files due to insufficient file extension checks in the `UPCP_Handle_File_Upload` function.
Description
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file field and access them via the upcp-product-file-uploads directory to execute arbitrary code on the server.
Exploits (1)
This is a technical writeup detailing an arbitrary file upload vulnerability in WordPress Ultimate Product Catalogue Plugin v3.8.6. The vulnerability allows authenticated users to upload malicious files due to insufficient file extension checks in the `UPCP_Handle_File_Upload` function.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H