The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-15T12:15:44.681Z
Updated: 2024-08-03T01:48:40.397Z
Reserved: 2022-12-28T03:05:45.514Z
Link: CVE-2022-4774
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-15T13:15:09.623
Modified: 2024-11-21T07:35:55.007
Link: CVE-2022-4774
Redhat
No data.