Description
WordPress Plugin Uploadify is prone to a vulnerability that lets attackers upload arbitrary files. Successful exploitation of the vulnerability allows an attacker to upload a php code for example and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation. WordPress Plugin Uploadify version 1.0 is vulnerable.
Remediation
Disable the plugin
References
Related Vulnerabilities
Django Improper Input Validation Vulnerability (CVE-2011-4136)
WordPress Plugin Car Demon Multiple Vulnerabilities (1.7.97)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3946)
WordPress Plugin WP DSGVO Tools (GDPR) Cross-Site Scripting (3.1.23)
WordPress Plugin Backup and Restore WordPress-WPBackItUp Cross-Site Request Forgery (1.6.7)