HIGH🇵🇱 Wersja polska

CVE-2024-13908

CVSS 7.2v3.1pub. 2025-03-08upd. 2025-03-13

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Bestwebsoft Smtp

    APP
    Bestwebsoft
    < 1.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2017-18518MEDIUM6.1same product

The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.

CVE-2017-2171MEDIUM6.1same product

Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Conta...

CVE-2022-3393CRITICAL9.8PL ✓same vendor

CSV Injection w pluginie Post To CSV by BestWebSoft dla WordPress

CVE-2015-9335CRITICAL9.8PL ✓same vendor

SQL injection w pluginie Limit Attempts dla WordPress (obsługa adresu IP)

CVE-2015-9325CRITICAL9.8PL ✓same vendor

SQL injection w pluginie Visitors Online dla WordPress