WordPress Plugins and Themes Vulnerable to Limited File Upload Attack
CVE-2024-8725

6.8MEDIUM

What is CVE-2024-8725?

A vulnerability exists in several WordPress plugins and themes that allows for limited file upload due to inadequate validation mechanisms. This flaw permits authenticated attackers with Subscriber-level access and higher to upload .css and .js files to any location within the WordPress root directory. The exploit requires the Advanced File Manager Shortcodes plugin to be installed. As a result, this could potentially facilitate Stored Cross-Site Scripting attacks, causing further security risks for the affected websites.

Affected Version(s)

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution 0 <= 5.2.8

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TANG Cheuk Hei
.