PT-2026-95696 · Deleeuw+1 · Share-One-Drive | Onedrive & Sharepoint Plugin For Wordpress+3
CVE-2026-93031
·
Publicado
2026-09-18
·
Atualizado
2026-09-18
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download file to uploads function. This is due to the import action being registered for unauthenticated users via wp ajax nopriv , a missing capability check in can import(), and the imported file's extension and contents not being validated against get allowed mime types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Share-One-Drive | Onedrive & Sharepoint Plugin For Wordpress
Use-Your-Drive | Google Drive Plugin For Wordpress
Wp Cloud Plugins - Box
Wp Cloud Plugins - Dropbox