Tevolution < 2.3.0 - Arbitrary File Upload
criticalThe Tevolution Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'single_upload.php or single-upload.php' files in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server whic...
- CVSS:
- 9.8
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Apr 23, 2016