classyfrieds <= 3.8 - Arbitrary File Upload
highThe classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.
- CVSS:
- 8.8
- Affected:
- up to 3.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2021