CVE-2024-3112 Information
Jul 13, 2024
cve
Description
The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Reference
https://wpscan.com/vulnerability/fa6f01d6-aa3b-4452-9c5f-49bb227fea9d/
Share on: