Description

WordPress Plugin Kish Guest Posting is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input. An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application. WordPress Plugin Kish Guest Posting version 1.2 is vulnerable; other versions may also be affected.

Remediation

Restrict access to wp-content/plugins/kish-guest-posting/uploadify/scripts/uploadify.php (e.g. via .htaccess) or disable the plugin until a fix is available

References

Related Vulnerabilities