Loading
Generated remediation guidance and an executive summary. No account required.
The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers with Contributor+ level privileges to upload arbitrary files on the affected sites server which makes remote code execution possible.
Use CWE-434, Adsanityplugin vendor hub and Adsanity product page to widen CVE-2022-4949 into its surrounding weakness, vendor, and product context.