What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.
Explanation of Vulnerability in Simple Terms
Trustindex.io Widgets for Google Reviews versions up to 11.0.2 do not properly validate file uploads, allowing administrators to upload malicious files to the site. An attacker with admin access can upload files that execute code, modify site content, or disrupt service. The vulnerability requires high-level privileges and affects the entire site scope.
What an attacker can do
Upload and execute malicious files on the site with admin-level access.
Potential impact on your site
A compromised admin account can upload files that run code, steal data, or take the site offline.
Conditions required to exploit
Attacker must have administrator privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities