Podcasting Plugin by TSG < 3.0.5 - Remote File Inclusion
critical
The Podcasting Plugin by TSG plugin for WordPress is vulnerable to Remote File Inclusion of media files in versions up to, and including, 3.0.4.1 via the mediaplayer.swf file. This allows unauthenticated attackers to include remote files on the server.
- CVSS:
- 9.8
- Affected:
- up to 3.0.4.1
- Fixed in:
- 3.0.5
- Disclosed:
- May 25, 2014
Podcasting Plugin by TSG [podcasting] < 3.0.5 (closed)
unknown
The Podcasting Plugin by TSG plugin for WordPress is vulnerable to Remote File Inclusion of media files in versions up to, and including, 3.0.4.1 via the mediaplayer.swf file. This allows unauthenticated attackers to include remote files on the server.
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- May 25, 2014
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database