Product Referenceproduct
https://ms.wordpress.org/plugins/hs-brand-logo-slider CVE-2020-37227
HIGH
WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload
Record summary
CVE-2020-37227 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
HS Brand Logo SliderBrowse Heliossolutions / HS Brand Logo Slider | CVE List | 2.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File UploadExploitDB exploitby Net-HunterNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37227 ExploitDB-48913exploit
https://www.exploit-db.com/exploits/48913 Official Product Homepageproduct
https://www.heliossolutions.co/ VulnCheck Advisory: WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File UploadThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-hs-brand-logo-slider-unrestricted-file-upload