What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.
Explanation of Vulnerability in Simple Terms
Theme Editor versions up to 2.7.1 allow authenticated administrators to upload files without proper validation. An attacker with admin access can upload malicious files to compromise the site. The vulnerability affects file integrity and confidentiality. Update to a version newer than 2.7.1 to remediate.
What an attacker can do
Upload malicious files to the site if they have admin access.
Potential impact on your site
A compromised admin account can upload files that execute code or expose sensitive data.
Conditions required to exploit
Attacker must have administrator-level privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities