Business Hours Pro <= 5.5.0 - Arbitrary File Upload
criticalThe Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.
- CVSS:
- 9.8
- Affected:
- up to 5.5.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 2, 2021