What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshipping & Affiliation with Amazon: from n/a through 2.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshipping & Affiliation with Amazon: from n/a through 2.1.2.
Explanation of Vulnerability in Simple Terms
The Dropshipping & Affiliation with Amazon plugin for WordPress allows authenticated users with low privileges to upload files without restriction. An attacker can upload malicious files—including PHP scripts—to execute arbitrary code on the site. The vulnerability affects all versions up to 2.1.2 and has a CVSS score of 9.9, indicating severe risk to site integrity and confidentiality.
What an attacker can do
Upload and execute malicious files, including PHP code, to take control of the site.
Potential impact on your site
Site can be fully compromised; attacker gains ability to read/modify data, create admin accounts, or inject malware.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities