vendor:
User Meta
by:
Adrien Thierry
7,5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: User Meta
Affected Version From: 1.1.1
Affected Version To: 1.1.1
Patch Exists: Yes
Related CWE: N/A
CPE: a:user-meta:user_meta:1.1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
WordPress User Meta Version 1.1.1 Arbitrary File Upload
An attacker can upload arbitrary files to the vulnerable Wordpress User Meta Version 1.1.1 plugin by exploiting the uploader.php file. The attacker can then access the uploaded file by accessing the filepath shown in the result of the exploit.
Mitigation:
Upgrade to the latest version of the Wordpress User Meta plugin.