Dropshipping & Affiliation with Amazon [wp-amazon-shop] <= 2.1.2 (unfixed + closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshipping & Affiliation with Amazon: from n/a through 2.1.2.
- Affected:
- up to 2.1.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2023
CVE-2023-31215 on NVD →
Dropshipping & Affiliation with Amazon <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Dropshipping & Affiliation with Amazon plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on files imported from a URL via the wpas_import_product_from_amazon() function called via an AJAX action in versions up to, and including, 2.1.2. This makes it possible for authen...
- CVSS:
- 8.8
- Affected:
- up to 2.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 3, 2023
CVE-2023-31215 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database