What the vulnerability does
01Description
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
What the vulnerability does
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
Explanation of Vulnerability in Simple Terms
The Squirrly SEO WordPress plugin through version 12.1.10 does not properly validate file uploads, allowing authenticated users to upload arbitrary files to the site. An attacker with a low-privilege account can upload malicious files that may compromise site integrity or enable further attacks. Update the plugin immediately to a version newer than 12.1.10.
What an attacker can do
Upload arbitrary files to the site, potentially including executable code or malware.
Potential impact on your site
Malicious files could be uploaded to your site, leading to data theft, malware distribution, or site defacement.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (subscriber or contributor level or higher).
Key dates
External resources
Related vulnerabilities