CVE-2018-25436
Published
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT
Description
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.
<p>If you have a WooCommerce store based in Australia and need the best domestic and international shipping rates on checkout, then look no further.<br />
Our freight aggregation system will match the best courier, at the best rate for each and every order placed on checkout.</p>
<ul>
<li>Displays cheapest courier rate on checkout</li>
<li>Seller saves money on freight & Buyer saves money on freight</li>
<li>Increase your sales conversions Australia-wide</li>
<li>Increase your sales conversions Internationally</li>
<li>Generate Shipping Labels with ease</li>
<li>Automatically books courier to make collection next day</li>
<li>Tracking</li>
<li>Insurance</li>
<li>Try our Multi Carrier system FREE for 30 days</li>
<li>Training, support, video tutorials available</li>
<li>If you wish to continue using our Multi Carrier Plugin subscribe to a monthly plan </li>
</ul>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/nTqZ5VYLbg8?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<p>We back this system up with excellent customer service support, phone, email, live chat support 18 hours a day. Contact us on 1300 748 510.</p>