WP Zone Inline Image Upload for BBPress
cpe:2.3:a:wpzone:inline_image_upload_for_bbpress:*:*:*:*:wordpress:*:*
- <= 1.1.19
A vulnerability allowing arbitrary file uploads has been identified in the Inline Image Upload for BBPress plugin for WordPress, affecting all versions through 1.1.19. The issue arises from inadequate validation of file extensions in the upload process. This vulnerability enables authenticated attackers with Subscriber-level access or higher to upload arbitrary files to the server, potentially leading to remote code execution. Additionally, if the 'Allow guest users without accounts to create topics and replies' setting is activated, unauthenticated attackers could exploit this vulnerability.
Exploitation of this vulnerability could allow for arbitrary file uploads, with the potential for remote code execution, depending on the nature of the uploaded files.
To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can upload files through the image upload feature in BBPress forum topics or replies. If the 'Allow guest users without accounts to create topics and replies' setting is enabled, this vulnerability can be exploited by unauthenticated users as well.
Users are advised to update the Inline Image Upload for BBPress plugin to version 1.1.20 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.