WordPress Community Forum
WordPress Support => WordPress Vulnerability => Topic started by: Kailash on Jun 15, 2022, 09:58 AM
WordPress eaSYNC plugin <= 1.1.15 - Unauthenticated Arbitrary File Upload vulnerability
Plugin name: Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC
Vulnerable versions: <= 1.1.15
Fixed in: 1.1.16
CVE ID: CVE-2022-1952
Classification: Arbitrary File Upload
Publicly disclosed: 2022-06-15
Vulnerability Details
Unauthenticated Arbitrary File Upload vulnerability discovered by cydave in WordPress eaSYNC plugin (versions <= 1.1.15).
Solution
Update the WordPress eaSYNC plugin to the latest available version (at least 1.1.16).
Plugin Link: https://wordpress.org/plugins/easync-booking/