Arbitrary File Upload Vulnerability in User Submitted Posts Plugin for WordPress
CVE-2019-25138
9.8CRITICAL
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 June 2023
Summary
The User Submitted Posts plugin for WordPress contains a vulnerability that allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation in its usp_check_images function. This flaw can lead to the potential for remote code execution on the server. Users of affected versions, up to and including 20190312, are encouraged to update their plugins to mitigate the risks associated with this vulnerability.
Affected Version(s)
User Submitted Posts – Enable Users to Submit Posts from the Front End * < 20190426
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet