Beveiligingsadvies

CVE-2021-24721

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-11-08 17:35:14
Laatst bijgewerkt 2024-08-03 19:42:16
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.