2 results (0.001 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the function protect_aioseo_ajax of the file class.vaultpress-hotfixes.php of the component MailPoet Plugin. The manipulation leads to unrestricted upload. The attack can be launched remotely. • https://github.com/wp-plugins/vaultpress/commit/e3b92b14edca6291c5f998d54c90cbe98a1fb0e3 https://github.com/wp-plugins/vaultpress/releases/tag/1.6.1 https://vuldb.com/?ctiid.230263 https://vuldb.com/?id.230263 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely. Se ha encontrado una vulnerabilidad, clasificada como crítica, en el plugin VaultPress versión 1.8.4. • http://seclists.org/fulldisclosure/2017/Feb/95 https://vuldb.com/?id.97383 • CWE-94: Improper Control of Generation of Code ('Code Injection') •