Input validation vulnerability in WPE Indoshipping 2.5.0

The WPE Indoshipping plugin for WordPress is vulnerable to unauthorized file uploads, meaning that someone without permission can upload files to the server. This is because the upload-file.php file in versions up to 2.5.0 doesn’t have any security to make sure the type of file being uploaded is correct. This could allow a malicious attacker to upload files that allow them to access the server, potentially allowing them to execute code.

Detected in:

WPE Indoshipping open vulnerable versions: >= * <= 2.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.