The All-in-One WP Migration WordPress plugin before 7.41...
High severity
Unreviewed
Published
Mar 8, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Mar 7, 2022
Published to the GitHub Advisory Database
Mar 8, 2022
Last updated
Feb 3, 2023
The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.
References