ThreatPress

WordPress Vulnerabilities Database

Back

WordPress CsvWPeC Coupon Plugin <= 1.1 - Remote File Upload

Product
CsvWPeC Coupon
Description
This plugin is prone to a remote file upload vulnerability, because user input is not properly sanitized. It allows a malicious user to upload executable files to a vulnerable wordpress installation.
Solution
Update the plugin.
Classification
Type Remote File Inclusion
OWASP Top 10 A1: Injection
References
Vapid
CVE
Name CVE-N/A
Versions
Affected In <= 1.1
Fixed In 1.2
Disclosure date
2015-09-14
Credits
Larry W. Cashdollar