1 results (0.001 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install. The Zyrex Popup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zx_main_page function in versions up to, and including, 1.0. This makes it possible for authenticated attackers, with administrative privileges, to upload arbitrary files on the affected site's server which may make remote code execution possible. • https://wpscan.com/vulnerability/0fd0d7a5-9263-43b6-9244-7880c3d3e6f4 • CWE-434: Unrestricted Upload of File with Dangerous Type •