Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Viniciusmarangoni

#40921de 56,337
7.2CVSS total
Vulnerabilidades · 1
PT-2018-12284
7.2
2018-08-04
WordPress · Wordpress · CVE-2018-14028
**Name of the Vulnerable Software and Affected Versions** WordPress version 4.9.7 **Description** The issue allows for the upload of PHP files via the admin area without proper verification as ZIP files. Once uploaded, even though the plugin extraction fails, the PHP file remains in a predictable location within `wp-content/uploads`, enabling an attacker to execute the file. This poses a security risk, particularly in scenarios where an attacker cannot upload arbitrary PHP code into a valid plugin ZIP file due to restricted permissions in the `wp-content/plugins` directory. **Recommendations** For WordPress version 4.9.7, update to a version that includes the fix for this issue to prevent the upload and execution of unauthorized PHP files.