Protect uploads <= 0.3 - Authorization Bypass
mediumThe Protect uploads plugin for WordPress failed to use a capability check and leaked the nonce necessary to save changes in the protect-uploads-admin-settings-page.php file. This meant that attackers able to successfully load this file in the context of WordPress, such as through a separate local file inclusion vulnera...
- CVSS:
- 4.8
- Affected:
- up to 0.3
- Fixed in:
- 0.4
- Disclosed:
- Aug 13, 2022