Multiple Plugins by Trustindex.io <= (Various Versions)- Authenticated (Editor+) Arbitrary File Upload
mediumMultiple plugins for WordPress by Trustindex.io are vulnerable to arbitrary file uploads due to missing file type validation in the ~/tabs/feature_request.php file in various versions. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files on the affected site'...
- CVSS:
- 6.6
- Affected:
- up to 11.0.2
- Fixed in:
- 11.1
- Disclosed:
- Nov 22, 2023