Description
WordPress Plugin Instinct e-Commerce is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to sanitize user-supplied input. WordPress Plugin Instinct e-Commerce version 3.4 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
http://packetstormsecurity.com/files/view/71324/wpecomm-upload.txt
Related Vulnerabilities
WordPress Plugin E-Search Multiple Cross-Site Scripting Vulnerabilities (1.0)
WordPress 4.9.x PHP Object Injection (4.9 - 4.9.17)
Moodle Other Vulnerability (CVE-2022-40208)
Joomla! Core 1.5.x Security Bypass (1.5.0 - 1.5.6)
WordPress Plugin TAuto Poster includes Backdoor [Only if downloaded via the vendor website] (1.4.5)