Beta

Report

WP Tripadvisor Review Widgets <= 11.0.2 is vulnerable to Arbitrary File Upload vulnerability

Editor
Published
2023-11-27

Multiple plugins for WordPress by Trustindex.io are vulnerable to arbitrary file uploads due to missing file type validation in the ~/tabs/feature_request.php file in various versions. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This vulnerability may only be fully exploitable for RCE in unique scenarios where the server is overloaded and the unlink() is not triggered immediately following move_uploaded_file().

CVSS

Score:8

Severity:High

Version: 11.0.2

There is a patch available in v11.1 and we strongly recommend you update to this version as soon as possible.