TDO Mini Forms <= 0.13.9 - Arbitrary File Upload
criticalThe TDO Mini Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the tdomf-upload-inline.php file in versions up to, and including, 0.13.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make re...
- CVSS:
- 9.8
- Affected:
- up to 0.13.9
- Fix:
- No patched version reported
- Disclosed:
- Sep 4, 2012