AA-Team Premium SEO Pack <= 1.8.0 - Local File Disclosure and Arbitrary File Upload
criticalThe AA-Team Premium SEO Pack plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.8.0 via the 'file_content' parameter. This makes it possible for unauthenticated attackers that include the default connection key to upload arbitrary files like shell scripts that can be used to...
- CVSS:
- 9.8
- Affected:
- up to 1.8.0
- Fix:
- No patched version reported
- Disclosed:
- May 1, 2015