Opt-In Downloads <= 4.07 - Authenticated (Subscriber+) Arbitrary File Upload
highThe Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_upload() function in all versions up to, and including, 4.07. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the af...
- CVSS:
- 8.8
- Affected:
- up to 4.07
- Fix:
- No patched version reported
- Disclosed:
- Dec 11, 2024