Mobile App Builder by WapPress <= 1.05 - Arbitrary File Upload
criticalVulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. There are no file upload authentication or capability checks which make it possible for attackers to upload arbitrary files on the affected sites server which may...
- CVSS:
- 9.8
- Affected:
- up to 1.05
- Fix:
- No patched version reported
- Disclosed:
- Mar 7, 2017