What the vulnerability does
01Description
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Explanation of Vulnerability in Simple Terms
Fluent Boards Pro versions up to 2.0.11 allow authenticated administrators to upload files without proper type validation. An attacker with admin privileges can upload executable files, potentially running their own code on the site. The vulnerability affects confidentiality, integrity, and availability of the entire WordPress installation.
What an attacker can do
Upload and execute arbitrary files on the site, gaining full control of the WordPress installation.
Potential impact on your site
A compromised admin account can lead to complete site takeover, data theft, and malware installation.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress admin panel.
Key dates
External resources
Related vulnerabilities