ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Product Add-Ons PLugin <= 1.1 - Arbitrary File Upload

Product
Product Add-Ons
Description
Because of this vulnerability, the attackers can upload the selected file to the directory /wp-content/uploads/product_files/ as upload.php.
Solution
Update the plugin.
Classification
Type Arbitrary File Upload
OWASP Top 10 A1: Injection
References
Plugin Vulnerabilities
CVE
Name CVE-N/A
Versions
Affected In <= 1.1
Fixed In 1.2
Disclosure date
2016-09-19
Submitter
ThreatPress