Is the WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from plugin safe?
Below are the known, publicly disclosed vulnerabilities of the WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from (WordPress) component. If you use it on your site, check the version and update it before the flaw gets exploited.
Known vulnerabilities
WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's: zdalne wykonanie kodu (RCE)
Zdalne wykonanie kodu (RCE) w komponencie WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's. Ocena zagrożenia: Wysoka (CVSS 8.8). Zaktualizuj podatny komponent do najnowszej wersji lub tymczasowo go wyłącz.
How to check whether this affects you
- Check the installed version of the WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from component in the admin panel.
- Compare it with the fixed version noted in the details of the relevant vulnerability above.
- If your version is older, update the component to the latest available.
- If a fix has not been released yet, temporarily disable the vulnerable element and watch your logs.
Is this plugin putting your site at risk?
We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are safe.
Request a free audit →