WordPress Autoptimize Shell Upload
Posted by deepcore on January 9, 2021 – 5:35 am
WordPress Autoptimize plugin suffers from a remote shell upload vulnerability. The ao_ccss_import AJAX call does not ensure that the file provided is a legitimate zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote code execution.
Post a reply
You must be logged in to post a comment.