Unrestricted File Upload Vulnerability in VideoWhisper Live Streaming Integration Plugin for WordPress
CVE-2014-1905

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
29 December 2014

Summary

The VideoWhisper Live Streaming Integration plugin for WordPress has a vulnerability that permits unrestricted file uploads, allowing attackers to upload malicious files by exploiting double extensions. A compromised file can subsequently be accessed via direct requests, leading to arbitrary PHP code execution on the server. This issue underscores the importance of securing file upload mechanisms to prevent unvalidated input from being executed.

References

EPSS Score

17% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.