vendor:
Work the Flow File Upload
by:
Claudio Viviani
7.5
CVSS
HIGH
Shell Upload Vulnerability
434
CWE
Product Name: Work the Flow File Upload
Affected Version From: 2.5.2002
Affected Version To: 2.5.2002
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:work_the_flow_file_upload
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux BackBox 4.0 / curl 7.35.0
2015
WordPress Work the flow file upload 2.5.2 Shell Upload Vulnerability
Work the Flow File Upload. Embed Html5 User File Uploads and Workflows into pages and posts. Multiple file Drag and Drop upload, Image Gallery display, Reordering and Archiving. This two in one plugin provides shortcodes to embed front end user file upload capability and / or step by step workflow.
Mitigation:
Upgrade to the latest version of the plugin (2.5.3)