The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the eos_plugin_reviews_restore_version() function in all versions up to, and including, 0.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files leveraging files included locally.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Dec 2024 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the eos_plugin_reviews_restore_version() function in all versions up to, and including, 0.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files leveraging files included locally. | |
| Title | PlugVersions – Easily rollback to previous versions of your plugins <= 0.0.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-24T09:21:51.310Z
Updated: 2024-12-24T14:41:01.068Z
Reserved: 2024-12-20T22:08:57.044Z
Link: CVE-2024-12881
Updated: 2024-12-24T14:40:57.493Z
Status : Received
Published: 2024-12-24T10:15:06.240
Modified: 2024-12-24T10:15:06.240
Link: CVE-2024-12881
No data.