CONTUS VIDEO COMMENTS [contus-video-comments] < 1.1
unknown[en] Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Oct 6, 2016
plugin
5 known security issues reported for the Contus Video Comments WordPress plugin. Most recent disclosed Oct 6, 2016.
Running Contus Video Comments on your site? Check whether your installed version is affected.
Scan your site free[en] Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
The Contus Video Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
The Contus Video Comments plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the file_put_contents function in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload .jpg images anywhere in the WordPress installation.
The Contus Video Comments plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the file_put_contents function in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload .jpg images anywhere in the WordPress installation.
The contus-video-comments WordPress plugin was affected by an Unauthenticated Remote JPG File Upload security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free