Wordpress Front-end Editor File Upload

Discussion in 'News Aggregator' started by Packet Storm, 16 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    The Wordpress Front-end Editor plugin contains an authenticated file upload vulnerability. We can upload arbitrary files to the upload folder, because the plugin also uses it's own file upload mechanism instead of the wordpress api it's possible to upload any file type.

    Continue reading...
     

Share This Page

Loading...