Arbitrary File Upload Vulnerability in WPBookit Plugin Pre-1.7
The WPBookit plugin for WordPress has a vulnerability that allows arbitrary file uploads. This happens because it does not properly check file types in the 'WPB_Profile_controller::handle_image_upload' function. Versions up to and including 1.6.9 are affected. Unauthenticated attackers can upload any files to the server of an affected site. This may lead to remote code execution.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
iqonic design wpbookit |