Vulnerability Bulletins

Episode 107: Two Plugin Vulnerabilities Target File Upload Capabilities


System information

   
Affected software Wordpress

Description

The Wordfence Threat intelligence team finds vulnerabilities in two plugins, the User Profile Picture plugin and the WooCommerce Upload Files plugin. WordPress 5.7 is set to release on Tuesday, March 9 with numerous enhancements for the block editor, a new robots.txt API, and a stay of execution on jQuery-migrate. A zero day affecting Microsoft Exchange […]

More info:

https://www.wordfence.com/blog/2021/03/episode-107-two-plugin-vulnerabilities-target-file-upload-capabilities/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2021-03-09
Ministerio de Defensa
CNI
CCN
CCN-CERT