← Back to browse · API

CVE-2020-36705

Severity
CRITICAL
CVSS
9.8
EPSS
0.06944
Risk score
41.63
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2020-24147, GHSA-MJVV-FCGJ-HPR2
Products
tunafish:Adning Advertising 0 ≤1.5.5
Sources
euvd EUVD-2020-24147

Description

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

References