CyberRota Analysis
AI-GeneratedThe Improve SEO WordPress plugin versions up to 2.0.11 are vulnerable due to insufficient validation of uploaded files, permitting unauthenticated users to upload malicious PHP files to a publicly accessible directory. This flaw can lead to remote code execution, compromising the integrity and security of the WordPress site. Website administrators using this plugin should prioritize immediate updates or mitigations to prevent potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.