Description
WordPress Plugin BePro Listings is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. WordPress Plugin BePro Listings version 2.2.0020 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.0022 or latest
References
Related Vulnerabilities
WordPress Plugin Insert Pages Multiple Vulnerabilities (3.6.1)
WordPress Plugin Easy Digital Downloads Attach Accounts to Orders Cross-Site Scripting (2.0.1)
WordPress Plugin ThemeREX Addons Remote Code Execution (All)
WordPress Plugin SAML SP Single Sign On-SSO login Unspecified Vulnerability (4.8.70)
WordPress Plugin NextGEN Gallery-WordPress Gallery Security Bypass (3.1.6)