The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the eos_plugin_reviews_restore_version() function in all versions up to, and including, 0.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files leveraging files included locally.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 24 Dec 2024 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the eos_plugin_reviews_restore_version() function in all versions up to, and including, 0.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files leveraging files included locally. | |
Title | PlugVersions – Easily rollback to previous versions of your plugins <= 0.0.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-24T09:21:51.310Z
Updated: 2024-12-24T14:41:01.068Z
Reserved: 2024-12-20T22:08:57.044Z
Link: CVE-2024-12881
Vulnrichment
Updated: 2024-12-24T14:40:57.493Z
NVD
Status : Received
Published: 2024-12-24T10:15:06.240
Modified: 2024-12-24T10:15:06.240
Link: CVE-2024-12881
Redhat
No data.