The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-27T20:19:02.028Z
Reserved: 2023-01-24T17:51:16.007Z
Link: CVE-2023-0477

Updated: 2024-08-02T05:10:56.447Z

Status : Modified
Published: 2023-03-13T17:15:12.480
Modified: 2024-11-21T07:37:15.560
Link: CVE-2023-0477

No data.