µAudio Player <= 0.6.2 - Remote File Inclusion
criticalThe µAudio Player plugin for WordPress is vulnerable to Remote File Inclusion of image files in versions up to, and including, 0.6.2 via the mediaplayer.swf file. This allows unauthenticated attackers to include remote files on the server.
- CVSS:
- 9.8
- Affected:
- up to 0.6.2
- Fix:
- No patched version reported
- Disclosed:
- May 25, 2014