WordPress Webinar Plugin
cpe:2.3:a:webinarpress:webinarpress:*:*:*:*:wordpress:*:*
- <= 1.33.24
A vulnerability exists in the WordPress Webinar Plugin - WebinarPress, in all versions through 1.33.24. The issue arises from a missing capability check on the 'sync-import-imgs' function, coupled with inadequate file type validation. This flaw enables authenticated attackers with subscriber-level access or higher to create arbitrary files, potentially leading to remote code execution.
Exploitation of this vulnerability allows for arbitrary file creation, which can be leveraged to execute remote code on the server.
Users are advised to update the WordPress Webinar Plugin - WebinarPress to version 1.33.25 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.