Unrestricted File Upload Vulnerability in VideoWhisper Live Streaming Integration Plugin for WordPress
CVE-2014-1905
Currently unrated
Summary
The VideoWhisper Live Streaming Integration plugin for WordPress has a vulnerability that permits unrestricted file uploads, allowing attackers to upload malicious files by exploiting double extensions. A compromised file can subsequently be accessed via direct requests, leading to arbitrary PHP code execution on the server. This issue underscores the importance of securing file upload mechanisms to prevent unvalidated input from being executed.
References
EPSS Score
17% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved