BePro Listings <= 2.2.0020 - Unauthenticated Arbitrary File Upload
criticalThe BePro Listings plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads in versions up to, and including, 2.2.0020 due to insufficient file type validation on the bepro_listings_save() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the server that may...
- CVSS:
- 9.8
- Affected:
- up to 2.2.0020
- Fixed in:
- 2.2.0021
- Disclosed:
- Jul 6, 2016