nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1103 CVE-2022-1103
HIGH
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
Record summary
CVE-2022-1103 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Advanced uploader | CVE List | 4.2 to ≤ 4.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)ExploitDB exploitby Roel van BeurdenNot analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/9ddeef95-7c7f-4296-a55b-fd3304c91c18