Arbitrary File Upload Vulnerability in Omni Secure Files Plugin by WordPress
CVE-2012-10064
Key Information:
- Vendor
Omnilogic
- Status
- Vendor
- CVE Published:
- 16 January 2026
Badges
What is CVE-2012-10064?
The Omni Secure Files plugin for WordPress prior to version 0.1.14 suffers from an arbitrary file upload vulnerability due to the lack of authentication and insufficient controls in the bundled plupload example endpoint. The vulnerable upload.php handler allows unauthorized users to upload files to the server, bypassing safe file type checks. This can potentially lead to serious security concerns, including remote code execution, if an attacker uploads a malicious executable file and is able to access it on the server.
Affected Version(s)
Omni Secure Files 0 < 0.1.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
