What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.
Explanation of Vulnerability in Simple Terms
BerqWP versions up to 1.7.6 allow unauthenticated attackers to upload files without restriction. An attacker can upload malicious files—such as PHP scripts—directly to the site, gaining the ability to run their own code and take full control. No authentication or user interaction is required; the vulnerability is exploitable over the network.
What an attacker can do
Upload and execute malicious files to run arbitrary code on the site.
Potential impact on your site
Complete site compromise: attackers can execute code, steal data, modify content, and disable the site.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities