Vulnerability Description
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advanced Uploader Project | Advanced Uploader | <= 4.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/9ddeef95-7c7f-4296-a55b-fd3304c91c18ExploitThird Party Advisory
- https://wpscan.com/vulnerability/9ddeef95-7c7f-4296-a55b-fd3304c91c18ExploitThird Party Advisory
FAQ
What is CVE-2022-1103?
CVE-2022-1103 is a vulnerability with a CVSS score of 8.8 (HIGH). The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
How severe is CVE-2022-1103?
CVE-2022-1103 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1103?
Check the references section above for vendor advisories and patch information. Affected products include: Advanced Uploader Project Advanced Uploader.