Input validation vulnerability in Woffice Core 5.4.21

The Woffice Core plugin for WordPress, which is used with the Woffice Theme, has a security issue that allows for unauthorized files to be uploaded. This happens because there is no check for the type of file being uploaded. This means that anyone with access to the site and a certain level of permission can upload harmful files that could allow for someone to take control of the website from a remote location.

Detected in:

Woffice Core fixed vulnerable versions: >= * <= 5.4.21

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.