WPDating <= 7.4.1 - Arbitrary File Upload
Strategic Overview
Vulnerability Overview
The WPDating plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 7.4.1. This is due to missing file type validation on one of the plugin's functions. While the source of information claims that this is a cross-site request forgery vulnerability that requires tricking an administrative user to click a link in order to exploit the vulnerability, we believe that this may be exploitable by unauthenticated users as well after analyzing the provided proof of concepts. This makes it possible for unauthenticated attackers to upload malicious files to the server.
Technical Analysis
REMEDIATION: Update to version 7.4.2, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C