The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/15f78aad-001c-4219-aa7e-46537e1357a2/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/15f78aad-001c-4219-aa7e-46537e1357a2/ | Exploit Third Party Advisory |
Configurations
History
06 May 2025, 16:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:tipsandtricks-hq:wp_emember:*:*:*:*:*:wordpress:*:* | |
First Time |
Tipsandtricks-hq wp Emember
Tipsandtricks-hq |
|
CWE | CWE-434 | |
References | () https://wpscan.com/vulnerability/15f78aad-001c-4219-aa7e-46537e1357a2/ - Exploit, Third Party Advisory |
13 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-13 06:15
Updated : 2025-05-06 16:50
NVD link : CVE-2024-5080
Mitre link : CVE-2024-5080
JSON object : View
Products Affected
tipsandtricks-hq
- wp_emember
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type