← Back to CVE List

CVE-2021-34639

Published: 2021-08-05T21:15Z
Last Modified: 2025-03-21T16:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt