CVE-2020-37227

HIGH

WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37227. PoCs published by Net-Hunter.

AI-analyzed exploit summary This exploit demonstrates an authenticated file upload vulnerability in WordPress Plugin HS Brand Logo Slider 2.1, where client-side extension validation can be bypassed to upload arbitrary PHP files, leading to remote code execution.

Description

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution.

Exploits (1)

exploitdb WORKING POC
by Net-Hunter · textwebappsphp
https://www.exploit-db.com/exploits/48913

This exploit demonstrates an authenticated file upload vulnerability in WordPress Plugin HS Brand Logo Slider 2.1, where client-side extension validation can be bypassed to upload arbitrary PHP files, leading to remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin HS Brand Logo Slider 2.1
Auth required
Prerequisites: Authenticated WordPress user access · Burp Suite or similar intercepting proxy
devstral-2 · analyzed May 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-48913
https://www.exploit-db.com/exploits/48913
Product product
Official Product Homepage
https://www.heliossolutions.co/
Product product
Product Reference
https://ms.wordpress.org/plugins/hs-brand-logo-slider/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload
https://www.vulncheck.com/advisories/wordpress-plugin-hs-brand-logo-slider-unrestricted-file-upload

Scores

CVSS v3 8.8
EPSS 0.0054
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Heliossolutions/HS Brand Logo Slider 2.1
Published May 16, 2026
Tracked Since May 16, 2026