The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

ZeroFox Blog


The best practices, latest research and breaking news in social media, mobile, digital and collaboration platforms.

Listed: