3 results (0.007 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

31 Jan 2024 — Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4. Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en bPlugins LLC Icons Font Loader. Este problema afecta a Icons Font Loader: desde n/a hasta 1.1.4. The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in versions up to, and including, 1.1... • https://patchstack.com/database/vulnerability/icons-font-loader/wordpress-icons-font-loader-plugin-1-1-4-arbitrary-file-upload-vulnerability?_s_id=cve • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 8.3EPSS: 4%CPEs: 1EXPL: 0

01 Nov 2023 — The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. El complemento Icons Font Loader para WordPress es vulnerable a cargas de archivos arbitrarias debido a la falta de validación ... • https://plugins.trac.wordpress.org/changeset/2987296/icons-font-loader • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0

16 Oct 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2. La neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ("Inyección SQL") en bPlugins LLC Icons Font Loader permite la inyección SQL. Este problema afecta a Icons Font Loader: desde n/a hasta 1.1.2. The Icons Font Loader plugin for WordPress is vulner... • https://patchstack.com/database/vulnerability/icons-font-loader/wordpress-icons-font-loader-plugin-1-1-2-subscriber-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •