← back
CVE-2022-1952observed exploitationCWE-434

eaSYNC < 1.1.16 - Unauthenticated Arbitrary File Upload

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 23%
from disclosure to weapon
Published on NVDJul 11
VulnCheck+560d
exploitation probability
23%top 2% of all CVEs
observed exploitation
yesVulnCheck
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.