The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T17:30:07.527Z

Reserved: 2024-02-05T08:57:43.929Z

Link: CVE-2021-4436

cve-icon Vulnrichment

Updated: 2024-08-03T17:30:07.527Z

cve-icon NVD

Status : Modified

Published: 2024-02-05T09:15:43.013

Modified: 2024-11-21T06:37:43.550

Link: CVE-2021-4436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.