The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-05-16T14:30:27

Updated: 2022-05-16T14:30:27

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-25119

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-16T15:15:08.430

Modified: 2022-05-25T13:45:34.900


Link: CVE-2021-25119

JSON object: View

cve-icon Redhat Information

No data.

CWE