What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.
Explanation of Vulnerability in Simple Terms
Export Import Menus allows authenticated users to upload files without proper validation, enabling them to upload malicious code to the site. An attacker with low-level access can execute arbitrary PHP code, compromise the entire WordPress installation, and access sensitive data. The vulnerability affects all versions up to 1.8.0.
What an attacker can do
Upload and execute malicious PHP code on the site, gaining full control of WordPress.
Potential impact on your site
Complete site compromise, data theft, and malware injection possible with any authenticated user account.
Conditions required to exploit
Attacker needs a low-privilege user account (subscriber or higher) on the WordPress site.
Key dates
External resources
Related vulnerabilities