BePro Listings <= 2.2.0020 - Unauthenticated Arbitrary File Upload
2016-07-06 00:00
AnonymousStrategic Overview
StatusPatched in 2.2.0021
Affected PluginBePro Listings
Affected Version
<= 2.2.0020CVSS9.8Critical
CVE
N/AVulnerability Overview
The BePro Listings plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads in versions up to, and including, 2.2.0020 due to insufficient file type validation on the bepro_listings_save() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the server that may make remote code execution possible.
Technical Analysis
REMEDIATION: Update to version 2.2.0021, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C