PT-2026-67969 · WordPress · Zportals
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
zportals WordPress plugin versions prior to 6.3.4
Description
The plugin fails to properly validate uploaded files by trusting the client-supplied content type and preserving the original file extension. This allows any authenticated user with Subscriber privileges or higher to upload arbitrary PHP files, which can lead to remote code execution (RCE), a process where an attacker executes malicious commands on the host server.
Recommendations
Update zportals WordPress plugin to version 6.3.4 or later.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zportals