How I Find Another Arbitrary File Upload Vulnerability and Bypass the Patch Twice

6 months ago 30
BOOK THIS SPACE FOR AD
ARTICLE AD

WordPress Bug Bounty Write-up for Patchstack Competition #2

Peng Zhou

3 min read

Just now

--

I am writing this article to share one of my most interesting bug-bounty experiences when I participated in the Patchstack monthly competition. The original vulnerability I found here is an Arbitrary File Upload (AFU) from the WordPress plugin church-admin <=4.1.5, and the two patch bypasses are from its versions <=4.1.7 and <=4.1.9 respectively. In March 2024, these vulnerabilities were patched…

Read Entire Article