WordPress.MailPoet.Newsletters.Unauthenticated.File.Upload
Description
This indicates an attack attempt against an arbitrary File Upload vulnerability in Wordpress MailPoet Newsletters (wysija-newsletters) plugins.
The vulnerability is due to insufficient input validation in the application when handling an unauthenticated file upload. It allows a remote attacker to upload an arbitrary file onto vulnerable systems.
Affected Products
MailPoet Newsletters (wysija-newsletters) 2.6.7 and prior
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-05-20 | 15.847 | Sig Added |
2019-11-19 | 14.726 | Sig Added |
2019-02-01 | 14.540 | Name:Wordpress. MailPoet. Newsletters. Unauthenticated. File. Upload:WordPress. MailPoet. Newsletters. Unauthenticated. File. Upload |