WordPress Plugin Vulnerabilities
WordPress File Upload <= 3.4.0 - Unauthenticated Malicious File Upload
Description
The WordPress plugin wp-file-upload does not adequately check the filetype before allowing it to be uploaded. It also uploaded files with execute permissions, allowing malicious payloads to be uploaded.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Submitter
Garth Mortensen
Submitter website
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2015-10-29 (about 10 years ago)
Added
2015-11-09 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)