RBX Gallery < 3.1 - Arbitrary File Upload
criticalUnrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin before 3.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/rbxslider.
- CVSS:
- 9.8
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Jun 8, 2012