WordPress MailPoet Newsletters (wysija-newsletters) unauthenticated file upload

Description

The WordPress plugin "MailPoet Newsletters" (wysija-newsletters) before version 2.6.8 is vulnerable to an unauthenticated file upload. An attacker can use the Upload Theme functionality to upload a zip file containing a PHP shell.

Remediation

Upgrade to the latest version of MailPoet Newsletters (this issue was fixed in version 2.6.8).

References