WP E-Signature [e-signature] < 1.5.6.8
unknown
Unauthenticated Remote Code Execution (RCE) vulnerability found by John Castro in WordPress WP E-Signature premium plugin (versions <= 1.5.6.5).
- Affected:
- up to 1.5.6.8
- Fixed in:
- 1.5.6.8
- Disclosed:
- Jan 13, 2021
e-signature < 1.5.6.8 - Unauthenticated Remote Code Execution
critical
The e-signature plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.5.6.8. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.5.6.8
- Fixed in:
- 1.5.6.8
- Disclosed:
- Jan 11, 2021
WP E-Signature [e-signature] < 1.5.6.8
unknown
The e-signature plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.5.6.8. This allows unauthenticated attackers to execute code on the server.
- Affected:
- up to 1.5.6.8
- Fixed in:
- 1.5.6.8
- Disclosed:
- Jan 11, 2021
WP E-Signature [e-signature] < 1.5.6.8
unknown
The AJAX sif_upload_file allowed the authorised extensions to be provided in the request, which result in unauthenticated arbitrary file upload and lead to RCE
- Affected:
- up to 1.5.6.8
- Fixed in:
- 1.5.6.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database