What the vulnerability does
01Description
Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
Explanation of Vulnerability in Simple Terms
An authenticated administrator can upload arbitrary files to the site through this WordPress plugin, bypassing file type restrictions. The plugin fails to properly validate file uploads, allowing an attacker with admin privileges to upload malicious files like PHP scripts. This can lead to unauthorized code execution and full site compromise.
What an attacker can do
Upload arbitrary files to the site and execute malicious code.
Potential impact on your site
A compromised admin account can upload malware, steal data, or take over the entire site.
Conditions required to exploit
Attacker must have WordPress administrator privileges.
Key dates
External resources