Remote Code Execution in Videowhisper Video Presentation Plugin for WordPress
CVE-2015-9272
What is CVE-2015-9272?
The Videowhisper Video Presentation Plugin version 3.31.17 for WordPress contains a vulnerability that allows remote attackers to execute arbitrary code. This vulnerability arises due to improper handling of file uploads in the script vp/vw_upload.php, where files ending with 'html' are incorrectly treated as safe. Attackers can exploit this oversight by uploading a malicious file with a .phtml extension that contains executable PHP code, leading to unauthorized actions and potential compromise of the WordPress site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability Reserved
Vulnerability published