Security Advisory

CVE-2021-24311

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-06-01 11:33:29
Last updated 2024-08-03 19:28:23
Assigner WPScan
State PUBLISHED

Description

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.