What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.
Explanation of Vulnerability in Simple Terms
Icons Font Loader versions up to 1.1.4 allow authenticated administrators to upload files without proper validation. An attacker with admin access can upload malicious files to the site, potentially including executable code. This vulnerability requires high-level privileges to exploit but can lead to full site compromise once exploited.
What an attacker can do
Upload malicious files to the site, potentially including executable code or backdoors.
Potential impact on your site
A compromised admin account can be used to upload and execute malicious code, leading to full site takeover.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities