FileOrganizer <= 1.0.9 - Authenticated (Subscriber+) Arbitrary File Upload
Published Oct 29, 2024
8.8
HIGHCVSS 3.1
EPSS 2.35%
Description
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: The FileOrganizer Pro plugin must be installed and active to allow Subscriber+ users to upload files.
Affected products
-
- Version 0StatusaffectedConstraints<=1.0.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Softaculous | FileOrganizer – WordPress File Manager | unaffected |
|
- ≤ 1.0.9
-
- Version 0StatusaffectedConstraints<=1.0.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Softaculous | Fileorganizer | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
Change history (0)
No recorded changes yet.