WordPress Plugin Vulnerabilities
Ultimate Product Catalogue <= 3.1.1 - Unauthenticated File Upload
Description
By sending a specially-crafted HTTP POST request, a remote unauthenticated attacker can exploit this issue to upload arbitrary file and execute it in the context of the web server process.
Proof of Concept
Affects Plugins
References
Miscellaneous
Submitter
Luca Ercoli
Submitter website
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2015-04-22 (about 11 years ago)
Added
2015-04-26 (about 11 years ago)
Last Updated
2019-10-25 (about 6 years ago)