Filtered by vendor Imagements Project
Subscriptions
Filtered by product Imagements
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-24236 | 1 Imagements Project | 1 Imagements | 2024-11-21 | 9.8 Critical |
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE. |
Page 1 of 1.