8.8
CVE-2016-20075
- EPSS 0.33%
- Veröffentlicht 15.06.2026 12:00:43
- Zuletzt bearbeitet 15.06.2026 20:50:47
- CVE-Watchlists
- Unerledigt
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
Ultimate Product Catalog <= 4.4.48 - Authenticated (Contributor+) Arbitrary File Upload
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file field and access them via the upcp-product-file-uploads directory to execute arbitrary code on the server.
Mögliche Gegenmaßnahme
Ultimate Product Catalog: Update to version 5.0.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerEtoilewebdesign
≫
Produkt
Ultimate Product Catalog
Version
3.8.6
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Ultimate Product Catalog
Version
*-4.4.48
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.243 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://www.exploit-db.com/exploits/40012
http://www.EtoileWebDesign.com/
https://www.vulncheck.com/advisories/wordpress-ultimate-product-catalog-arbitrary-file-upload-rce
https://www.wordfence.com/threat-intel/vulnerabilities/id/3b6ae26e-9262-4241-81d1-d5522bd35345