ACF Frontend display [acf-frontend-display] <= 2.0.6 (unfixed + closed)
unknown
[en] The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
- Affected:
- up to 2.0.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2019
CVE-2015-9479 on NVD →
ACF Frontend display [acf-frontend-display] < 2.0.6 (closed)
unknown
ACF Frontend Display plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer.
Upgrade the plugin.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 7, 2015
ACF Frontend Display <= 2.0.6 - Unauthenticated Arbitrary File Upload
critical
The ACF-Frontend-Display plugin through 2.0.6 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
- CVSS:
- 9.8
- Affected:
- up to 2.0.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 6, 2015
CVE-2015-9479 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database