Csv2WPeC Coupon <= 1.1 - Arbitrary File Upload
critical
Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 in csv2wpecCoupon_FileUpload.php file.
- CVSS:
- 9.8
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 23, 2016
CVE-2015-1000013 on NVD →
Csv2WPeC Coupon [csv2wpec-coupon] <= 1.1 (closed)
unknown
[en] Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Oct 6, 2016
CVE-2015-1000013 on NVD →
Csv2WPeC Coupon [csv2wpec-coupon] < 1.2 (closed)
unknown
This plugin is prone to a remote file upload vulnerability, because user input is not properly sanitized. It allows a malicious user to upload executable files to a vulnerable wordpress installation.
Update the plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Sep 14, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database