Vulnerabilities > CVE-2022-1103 - Unspecified vulnerability in Advanced Uploader Project Advanced Uploader

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
advanced-uploader-project

Summary

The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

Vulnerable Configurations

Part Description Count
Application
Advanced_Uploader_Project
31