PT-2026-69355 · WordPress · Squeeze
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Squeeze WordPress plugin versions prior to 1.7.12
Description
Insufficient validation of file types or extensions during attachment-update actions allows users with the
upload files capability, such as those with Author privileges and above, to upload executable PHP files into the uploads directory. This flaw can lead to remote code execution, which is the ability of an attacker to execute arbitrary commands on the server.Recommendations
Update Squeeze WordPress plugin to version 1.7.12 or later.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Squeeze