WordPress Plugin Peugeot Music 1.0 Arbitrary File Upload
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
peugeot-music-plugin · Peugeot Musicpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/44737unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.