What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd Pro: from n/a through 6.18.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd Pro: from n/a through 6.18.10.
Explanation of Vulnerability in Simple Terms
SeedProd Pro versions up to 6.18.10 contain an unrestricted file upload vulnerability. An authenticated administrator can upload files without proper validation, potentially allowing them to run malicious code on the site. The vulnerability affects confidentiality, integrity, and availability of the entire site.
What an attacker can do
Upload and execute malicious files on the site, gaining control over the entire WordPress installation.
Potential impact on your site
A compromised admin account can lead to complete site takeover, data theft, and malware distribution.
Conditions required to exploit
Attacker must have administrator-level access to SeedProd Pro.
Key dates
External resources
Related vulnerabilities