Input validation vulnerability in Dropshipping & Affiliation with Amazon 2.1.2

The Dropshipping & Affiliation with Amazon plugin for WordPress has a security issue that allows attackers with a subscriber-level account or higher to upload any type of file to the site’s server. This is because the plugin doesn’t check to make sure the file type is valid when it’s imported from a URL. If an attacker is able to upload the wrong type of file, it might allow them to run code on the affected website, which is a very serious security issue. The plugin versions up to and including 2.1.2 are affected.

Detected in:

Dropshipping & Affiliation with Amazon open vulnerable versions: >= * <= 2.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.