What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
Explanation of Vulnerability in Simple Terms
WP Media Folder versions up to 5.7.2 allow authenticated users to upload files without proper validation. An attacker with low-level access can upload malicious files, including executable code, that execute on the server. This can lead to complete site compromise, data theft, and unauthorized modifications.
What an attacker can do
Upload and execute malicious files on the server, gaining control over the site.
Potential impact on your site
Attackers with basic user accounts can run code on your site, steal data, modify content, or take the site offline.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities