The User Post Gallery - UPG plugin for WordPress is...
Critical severity
Unreviewed
Published
Jan 3, 2023
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 3, 2023
Published to the GitHub Advisory Database
Jan 3, 2023
Last updated
Feb 3, 2023
The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command execution due to the use of a nopriv AJAX action and user supplied function calls and parameters in versions up to, and including 2.19. This makes it possible for unauthenticated attackers to call arbitrary PHP functions and perform actions like adding new files that can be webshells and updating the site's options to allow anyone to register as an administrator.
References