WORDFENCE-6a4d5a40-2ec0-468e-bafb-a713629f6006
critical
📛 Threat Title
Webcam Video Conference < 4.51 - Arbitrary File Upload
Description
The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the vw_upload.php file in versions before 4.51. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible. Affected software — plugin: Webcam Video Conference (affected: [*, 4.51)). CVSS 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Webcam Video ConferenceWordfence
Update to version 4.51, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.