Api2Cart Bridge Connector <= 1.1.0 - Arbitrary File Upload
critical
The Api2Cart Bridge Connector plugin for WordPress is vulnerable to arbitrary file uploads due to missing or incorrect file type validation in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...
- CVSS:
- 9.8
- Affected:
- 1.1.0 – 1.1.0
- Fixed in:
- 1.2.0
- Disclosed:
- Oct 28, 2022
CVE-2022-42698 on NVD →
Api2Cart Bridge Connector <= 1.1.0 - Arbitrary Code Execution
critical
The Api2Cart Bridge Connector plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.0. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.1.0
- Fixed in:
- 1.2.0
- Disclosed:
- Oct 28, 2022
CVE-2022-42497 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database