Cherry Plugin < 1.2.7 - Arbitrary File Upload
criticalThe Cherry Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and lack of access control via the upload.php file in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may ma...
- CVSS:
- 9.8
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Feb 10, 2015