What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.
Explanation of Vulnerability in Simple Terms
WP Child Theme Generator versions up to 1.0.9 allow authenticated administrators to upload files without proper validation. An attacker with admin access can upload malicious files to compromise the site's integrity, confidentiality, and availability. The vulnerability affects the entire WordPress installation due to scope change.
What an attacker can do
Upload malicious files to the WordPress site and execute arbitrary code.
Potential impact on your site
A compromised admin account can upload files that execute code, read data, or disable the site.
Conditions required to exploit
Attacker must have WordPress administrator privileges.
Key dates
External resources
Related vulnerabilities