What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Mollie Mollie Payments for WooCommerce.This issue affects Mollie Payments for WooCommerce: from n/a through 7.3.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Mollie Mollie Payments for WooCommerce.This issue affects Mollie Payments for WooCommerce: from n/a through 7.3.11.
Explanation of Vulnerability in Simple Terms
The Mollie Payments for WooCommerce plugin through version 7.3.11 does not properly validate file uploads, allowing an authenticated administrator to upload malicious files to the server. An attacker with admin access can execute arbitrary code, modify site data, or disrupt service. The vulnerability requires high-level privileges but affects the entire site once exploited.
What an attacker can do
Upload and execute malicious files on the server with admin-level access.
Potential impact on your site
A compromised admin account can lead to full site takeover, data theft, or malware installation.
Conditions required to exploit
Attacker must have WordPress administrator privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities