WordPress Plugins and Themes Vulnerable to Limited File Upload Attack
CVE-2024-8725
5.4MEDIUM
Summary
A vulnerability exists in several WordPress plugins and themes that allows for limited file upload due to inadequate validation mechanisms. This flaw permits authenticated attackers with Subscriber-level access and higher to upload .css and .js files to any location within the WordPress root directory. The exploit requires the Advanced File Manager Shortcodes plugin to be installed. As a result, this could potentially facilitate Stored Cross-Site Scripting attacks, causing further security risks for the affected websites.
Affected Version(s)
Advanced File Manager * <= 5.2.8
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
TANG Cheuk Hei