Security Advisory

CVE-2021-4436

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-02-05 09:02:44
Last updated 2026-01-09 21:05:31
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.