Auto Poster [auto-poster] <= 1.2 (unfixed + closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 7, 2024
CVE-2024-31345 on NVD →
Auto Poster <= 1.2 - Authenticated (Administrator+) Arbitrary File Upload
critical
The Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may mak...
- CVSS:
- 9.1
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 5, 2024
CVE-2024-31345 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database