CVE-2018-25436

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.

<p>If you have a WooCommerce store based in Australia and need the best domestic and international shipping rates on checkout, then look no further.<br /> Our freight aggregation system will match the best courier, at the best rate for each and every order placed on checkout.</p> <ul> <li>Displays cheapest courier rate on checkout</li> <li>Seller saves money on freight &amp; Buyer saves money on freight</li> <li>Increase your sales conversions Australia-wide</li> <li>Increase your sales conversions Internationally</li> <li>Generate Shipping Labels with ease</li> <li>Automatically books courier to make collection next day</li> <li>Tracking</li> <li>Insurance</li> <li>Try our Multi Carrier system FREE for 30 days</li> <li>Training, support, video tutorials available</li> <li>If you wish to continue using our Multi Carrier Plugin subscribe to a monthly plan </li> </ul> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/nTqZ5VYLbg8?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>We back this system up with excellent customer service support, phone, email, live chat support 18 hours a day. Contact us on 1300 748 510.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
2.59K