What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.
Explanation of Vulnerability in Simple Terms
WP Mail Log versions up to 1.1.2 do not properly validate file uploads, allowing authenticated users with low privileges to upload arbitrary files to the server. An attacker can upload malicious files such as PHP scripts to execute code, modify site content, or compromise the entire WordPress installation. This vulnerability affects all users of the plugin and requires immediate patching.
What an attacker can do
Upload and execute arbitrary files on the server, including PHP code, to take control of the site.
Potential impact on your site
Complete site compromise possible; attacker can run code, steal data, modify content, or lock you out.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities