The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-03T09:37:18.649Z
Updated: 2024-08-03T18:09:05.039Z
Reserved: 2024-07-29T22:05:23.872Z
Link: CVE-2024-7257
Vulnrichment
Updated: 2024-08-03T18:09:00.681Z
NVD
Status : Awaiting Analysis
Published: 2024-08-03T10:15:50.710
Modified: 2024-08-05T12:41:45.957
Link: CVE-2024-7257
Redhat
No data.