Description
WordPress Plugin WordPress File Upload is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. WordPress Plugin WordPress File Upload version 3.4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.1 or latest
References
Related Vulnerabilities
WordPress Plugin Booster for WooCommerce Security Bypass (5.4.3)
MySQL CVE-2019-2741 Vulnerability (CVE-2019-2741)
Squid Improper Input Validation Vulnerability (CVE-2014-7142)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2023-38371)
Oracle Database Server CVE-2006-3699 Vulnerability (CVE-2006-3699)