The Keydatas plugin for WordPress (known in Chinese as "简数采集器") is vulnerable to unrestricted file uploads due to missing file-type validation in the keydatas_downloadImages function in all versions up to and including 2.5.2. An unauthenticated attacker can upload arbitrary files to the server — potentially leading to remote code execution, site takeover, or other severe compromise.
id: CVE-2024-6220
info:
name: WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload
author: hnd388
...