The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-02T16:52:15.495Z
Updated: 2024-08-01T18:40:21.383Z
Reserved: 2024-02-15T20:15:56.171Z
Link: CVE-2024-1567
Vulnrichment
Updated: 2024-08-01T18:40:21.383Z
NVD
Status : Awaiting Analysis
Published: 2024-05-02T17:15:11.603
Modified: 2024-11-21T08:50:51.123
Link: CVE-2024-1567
Redhat
No data.