Description
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin Captcha by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (4.1.5)
WordPress Plugin Google Drive for WordPress Information Disclosure (2.2)
MySQL CVE-2019-2796 Vulnerability (CVE-2019-2796)
WordPress Plugin Redux Framework Cross-Site Request Forgery (4.1.20)
WordPress Plugin UpdraftPlus WordPress Backup Security Bypass (1.22.1)