Unrestricted File Upload Vulnerability in HS Brand Logo Slider by Helios Solutions
CVE-2020-37227
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 16 May 2026
Badges
What is CVE-2020-37227?
The HS Brand Logo Slider version 2.1 is susceptible to an unrestricted file upload vulnerability, which enables authenticated users to bypass the client-side validation of file extensions. By exploiting this vulnerability, malicious actors can upload arbitrary files by manipulating the upload requests directed to the logoupload parameter in the admin interface. This can lead to severe security risks, including the execution of remote code through the renaming of uploaded files to executable extensions such as .php.
Affected Version(s)
HS Brand Logo Slider 2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved