Elegant Themes (Multiple Versions) - Arbitrary File Upload
2020-08-03 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 4.5.3
Affected PluginDivi Builder
Affected Version
<= 4.3.2CVSS8.8High
CVE
CVE-2020-35945Vulnerability Overview
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than server side.
Technical Analysis
REMEDIATION: Update to version 4.5.3, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C