Simple Dropbox Upload < 1.8.8.1 - Arbitrary File Upload
criticalUnrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
- CVSS:
- 9.8
- Affected:
- up to 1.8.8.1
- Fixed in:
- 1.8.8.1
- Disclosed:
- Sep 14, 2013