Unrestricted File Upload Vulnerability in Gravity Upload Ajax Plugin for WordPress
CVE-2014-4972
What is CVE-2014-4972?
The Gravity Upload Ajax plugin for WordPress contains a vulnerability that allows attackers to upload files with executable extensions without proper validation. This flaw enables remote code execution, allowing malicious users to upload potentially harmful scripts to the server. Once the file is uploaded, attackers can access it through a direct URL, leading to severe security risks for affected WordPress installations. It is essential for users of this plugin to apply appropriate patches or take preventive measures to secure their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved