The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server
2024-07-13T06:15:04.163
2025-05-06T16:50:27.053
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | tipsandtricks-hq | wp_emember | < 10.6.6 | Yes |