WooCommerce Amazon Affiliates < 9.0.2.16 - Unauthenticated Arbitrary File Upload
criticalThe WooCommerce Amazon Affiliates plugin for WordPress is vulnerable to Arbitrary File Upload due to missing file type validation in the validate_connection function in versions before 9.0.2.16. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make re...
- CVSS:
- 9.8
- Affected:
- up to 9.0.2.16
- Fixed in:
- 9.0.2.16
- Disclosed:
- Apr 25, 2015