Unrestricted File Upload Vulnerability in Gravity Upload Ajax Plugin for WordPress
CVE-2014-4972
9.8CRITICAL
Summary
The Gravity Upload Ajax plugin for WordPress contains a vulnerability that allows attackers to upload files with executable extensions without proper validation. This flaw enables remote code execution, allowing malicious users to upload potentially harmful scripts to the server. Once the file is uploaded, attackers can access it through a direct URL, leading to severe security risks for affected WordPress installations. It is essential for users of this plugin to apply appropriate patches or take preventive measures to secure their applications.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved