WordPress Community Forum

WordPress Support => WordPress Vulnerability => Topic started by: Kailash on Jun 15, 2022, 09:58 AM

Title: WordPress eaSYNC plugin <= 1.1.15 - Arbitrary File Upload Vulnerability
Post by: Kailash on Jun 15, 2022, 09:58 AM
WordPress eaSYNC plugin <= 1.1.15 - Unauthenticated Arbitrary File Upload vulnerability

Plugin name: Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC
Vulnerable versions: <= 1.1.15
Fixed in: 1.1.16
CVE ID: CVE-2022-1952
Classification: Arbitrary File Upload
Publicly disclosed: 2022-06-15

Vulnerability Details

Unauthenticated Arbitrary File Upload vulnerability discovered by cydave in WordPress eaSYNC plugin (versions <= 1.1.15).

Solution

Update the WordPress eaSYNC plugin to the latest available version (at least 1.1.16).

Plugin Link: https://wordpress.org/plugins/easync-booking/