pb-embedFlash <= 1.5.1 - Remote File Inclusion
criticalThe pb-embedFlash plugin for WordPress is vulnerable to Remote File Inclusion with media files in versions up to, and including, 1.5.1 via the mediaplayer.swf file. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.
- CVSS:
- 9.8
- Affected:
- up to 1.5.1
- Fix:
- No patched version reported
- Disclosed:
- May 25, 2014