WPDating <= 7.4.1 - Arbitrary File Upload

2023-01-09 00:00
Anonymous

Strategic Overview

Status
Patched in 7.4.2
Affected PluginWPDating
Affected Version<= 7.4.1
CVSS8.8High
CVEN/A
View all WPDating vulnerabilities

Vulnerability Overview

The WPDating plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 7.4.1. This is due to missing file type validation on one of the plugin's functions. While the source of information claims that this is a cross-site request forgery vulnerability that requires tricking an administrative user to click a link in order to exploit the vulnerability, we believe that this may be exploitable by unauthenticated users as well after analyzing the provided proof of concepts. This makes it possible for unauthenticated attackers to upload malicious files to the server.

Technical Analysis

REMEDIATION: Update to version 7.4.2, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C