Arbitrary File Upload Vulnerability in ShopXO Payment Plugin
CVE-2020-26007
7.8HIGH
What is CVE-2020-26007?
An arbitrary file upload vulnerability exists in the upload payment plugin of ShopXO v1.9.0, allowing attackers to upload crafted PHP files which can lead to remote code execution on the server. This security issue can potentially allow malicious actors to compromise the affected systems, gain unauthorized access, and execute harmful scripts.