jQuery HTML5 File Upload <= 3.0 - Unauthenticated Arbitrary File Upload
critical
The jQuery HTML5 File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /UploadHandler.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make r...
- CVSS:
- 9.8
- Affected:
- up to 3.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 7, 2017
jQuery HTML5 File Upload <= 3.0 - Unauthenticated Settings Update
medium
The jQuery HTML5 File Upload plugin for WordPress is vulnerable to unauthenticated settings update in versions up to, and including 3.0, due to a lack of capability checking in the /jquery-html5-file-upload.php file. This makes it possible for unauthenticated attackers to update the plugin's settings which can contain...
- CVSS:
- 6.5
- Affected:
- up to 3.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 7, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database