ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Fast Image Adder Plugin <= 1.1 - Remote File Upload

Product
Fast Image Adder
Description
This plugin is prone to a remote file upload vulnerability, because the fast-image-adder-uploader.php file doesn't check if a user is authorized to upload files. It creates a random file name, but reports the name back to the user.
Solution
Update the plugin.
Classification
Type Arbitrary File Upload
OWASP Top 10 A1: Injection
References
Packet Storm Security
CVE
Name CVE-N/A
Versions
Affected In <= 1.1
Fixed In 1.2
Disclosure date
2015-07-10
Credits
Larry W. Cashdollar