2 results (0.003 seconds)

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 0

09 Aug 2022 — Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. Una vulnerabilidad de Edición/Descarga Arbitraria de Archivos Autenticado (admin+) en el plugin WPide de XplodedThemes versiones anteriores a 2.6 incluyéndola, en WordPress The WPide plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.6. This makes it possible for authenticated attackers, with administrator-level permissions and above, to upload arbi... • https://patchstack.com/database/vulnerability/wpide/wordpress-wpide-plugin-2-6-authenticated-arbitrary-file-edit-upload-vulnerability • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 1

03 Aug 2022 — The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue. El plugin WPIDE de WordPress versiones anteriores a 3.0, no sanea y comprueba el parámetro filename antes de usarlo en una sentencia require en el panel de administración, conllevando a un problema de inclusión de archivos locales The WPIDE plugin for WordPress is vulnerable to Local File Inclusion in versions up t... • https://wpscan.com/vulnerability/f6091d7b-97b5-42f2-b2f4-09a0fe6d5a21 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •