CVE-2021-39317

CVE-2021-39317

Versions up to, and including, 1.0.6, of the Access Demo Importer WordPress plugin are vulnerable to arbitrary file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the ~/inc/demo-functions.php.

Source: CVE-2021-39317

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다