Arbitrary File Upload Vulnerability in Responsive Thumbnail Slider for WordPress
CVE-2015-10144
8.8HIGH
What is CVE-2015-10144?
The Responsive Thumbnail Slider plugin for WordPress has a security flaw that allows authenticated users, including those with subscriber-level access, to exploit the image uploader feature. Due to insufficient sanitization of file types, these attackers can upload arbitrary files to the server. This vulnerability can lead to unauthorized remote code execution via a double extension attack, jeopardizing the integrity and security of the affected sites.
Affected Version(s)
Thumbnail carousel slider * < 1.0.1