SupportCandy <= 2.0.0 - Arbitrary File Upload

Affects Plugin

fixed in version 2.0.1

References

CVE 2019-11223
URL https://cert.kalasag.com.ph/news/research/vulnerable-wordpress-plugin-lets-you-take-over-websites/

Classification

Type UPLOAD
CWE CWE-434

Miscellaneous

Views 1523
Verified No
WPVDB ID 9488

Timeline

Publicly Published 2019-04-17 (4 months ago)
Added 2019-08-01 (23 days ago)
Last Updated 2019-08-01 (23 days ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin