First published: Tue Dec 26 2023(Updated: )
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpvibes Wp Mail Log | <1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.