header-logo
Suggest Exploit
vendor:
WP Marketplace
by:
Sammy FORGIT
8,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: WP Marketplace
Affected Version From: 1.5.0
Affected Version To: 1.6.1
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wp_marketplace
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

WordPress Plugins – WP Marketplace Shell Upload Vulnerability

A vulnerability in the WP Marketplace plugin for Wordpress allows an attacker to upload a malicious PHP file to the server. This can be done by sending a POST request to the uploadify.php file with the malicious file in the Filedata parameter. The malicious file can then be accessed at the uploadify directory on the server.

Mitigation:

Upgrade to version 1.6.2 or later of the WP Marketplace plugin.
Source

Exploit-DB raw data: