Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCE
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 3.0%
from disclosure to weapon
Published on NVDApr 22
VulnCheckApr 2
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
yesVulnCheck
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.
Affected products
Unknown · Business Hours Pro