|
Medium
|
All-in-One WP Migration and Ba=
ckup <=3D 7.86 - Authenticated (Administrator ) Arbitrary PHP Code Injec=
tion
The All=
-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbit=
rary PHP Code Injection due to missing file type validation during the expo=
rt in all versions up to, and including, 7.86. This makes it possible for a=
uthenticated attackers, with Administrator-level access and above, to creat=
e an export file with the .php extension on the affected site's server=
, adding an arbitrary PHP code to it, which may make remote code execution =
possible.
Source: Wordfence
|
|