The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/10528cb2-12a1-43f7-9b7d-d75d18fdf5bb | third party advisory |
https://codecanyon.net/item/business-hours-pro-wordpress-plugin/9414879 | product third party advisory |