What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPress Cover: from n/a through 2.1.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPress Cover: from n/a through 2.1.4.2.
Explanation of Vulnerability in Simple Terms
BuddyPress Cover allows unauthenticated attackers to upload files without restriction. An attacker can upload malicious files—including PHP scripts—directly to the site without needing an account or user interaction. This enables running arbitrary code on the server, compromising the entire site and any data it contains.
What an attacker can do
Upload and execute malicious files on the site without authentication.
Potential impact on your site
Complete site compromise: attackers can run code, steal data, modify content, or take the site offline.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities