4 results (0.001 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

12 Feb 2024 — Missing Authorization vulnerability in Skymoon Labs MoveTo.This issue affects MoveTo: from n/a through 6.2. Vulnerabilidad de autorización faltante en Skymoon Labs MoveTo. Este problema afecta a MoveTo: desde n/a hasta 6.2. The moveto plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, leading to site takeover. • https://patchstack.com/database/vulnerability/moveto/wordpress-moveto-plugin-6-2-unauthenticated-arbitrary-file-deletion-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-862: Missing Authorization •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

12 Feb 2024 — Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. Vulnerabilidad de autorización faltante en Skymoonlabs MoveTo. Este problema afecta a MoveTo: desde n/a hasta 6.2. The moveto plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to update arbitrary WordPress options, potentially leading to site takeover. • https://patchstack.com/database/vulnerability/moveto/wordpress-moveto-plugin-6-2-unauthenticated-arbitrary-wordpress-settings-change-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

12 Feb 2024 — Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en Skymoonlabs MoveTo. Este problema afecta a MoveTo: desde n/a hasta 6.2. The moveto plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknown function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to u... • https://patchstack.com/database/vulnerability/moveto/wordpress-moveto-plugin-6-2-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

12 Feb 2024 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. The MoveTo plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr... • https://patchstack.com/database/vulnerability/moveto/wordpress-moveto-plugin-6-2-unauthenticated-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •