MemberPress Downloads <= 1.2.5 - Authenticated (Subscriber+) Arbitrary File Upload
high
The MemberPress Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capabilities checks on one of its AJAX endpoints in versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above...
- CVSS:
- 8.8
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Sep 19, 2022
Memberpress Downloads [memberpress-downloads] < 1.2.6
unknown
Authenticated Arbitrary File Upload vulnerability discovered by WPScan in WordPress Memberpress Downloads premium plugin (versions <= 1.2.4).
No patched version available.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Sep 19, 2022
Memberpress Downloads [memberpress-downloads] < 1.2.6
unknown
The MemberPress Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capabilities checks on one of its AJAX endpoints in versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Sep 19, 2022
Memberpress Downloads [memberpress-downloads] < 1.2.6
unknown
The plugin does not properly check user capabilities in its file uploading AJAX endpoint, relying on WordPress nonces to do so. Unfortunately, the nonce can be leaked by any logged-in users, like subscribers. Since the Uploader library they use does not check file extensions at all, this may lead to RCE on sites runnin...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database