Headline
CVE-2022-38140: WordPress SEO Plugin by Squirrly SEO plugin <= 12.1.10 - Auth. Arbitrary File Upload vulnerability - Patchstack
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
Solution
Update the WordPress SEO Plugin by Squirrly SEO plugin to the latest available version (at least 12.1.11).
Yeraisci discovered and reported this Arbitrary File Upload vulnerability in WordPress SEO Plugin by Squirrly SEO Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 12.1.11.
1 other known vulnerability for this pluginTo plugin page
Report to Patchstack Alliance bounty platform and earn monthly cash prizes.
Learn more