CVE-2021-38360

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/09/2021
Last modified:
21/09/2021

Description

The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wp-publications_project:wp-publications:-:*:*:*:*:wordpress:*:*