Upload.am File Hosting VPN <= 1.0.0 - Authenticated (Contributor+) Arbitrary Options Disclosure
mediumThe Upload.am – File Hosting & VPN plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'upload_am_get_option' AJAX endpoint in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- CVSS:
- 5.3
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Sep 29, 2025