Vulnerabilities > WC Marketplace > WC Catalog Enquiry > 2.3.7

DATE CVE VULNERABILITY TITLE RISK
2019-08-27 CVE-2017-18592 Unrestricted Upload of File with Dangerous Type vulnerability in Wc-Marketplace WC Catalog Enquiry
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
network
low complexity
wc-marketplace CWE-434
7.5