The wp-eMember WordPress plugin before 10.6.6 does not...
High severity
Unreviewed
Published
Jul 13, 2024
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
Jul 13, 2024
Published to the GitHub Advisory Database
Jul 13, 2024
Last updated
May 6, 2025
The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server
References