Uploader <= 1.0.4 - Arbitrary File Upload
critical
The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/uploadify/uploadify.php' file in versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote...
- CVSS:
- 9.8
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014
Uploader <= 1.0.4 - Multiple Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014
CVE-2013-2287 on NVD →
Uploader [uploader] <= 1.0.4 (unfixed + closed)
unknown
The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/uploadify/uploadify.php' file in versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote...
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014
Uploader [uploader] <= 1.0.4 (closed)
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Apr 4, 2014
CVE-2013-2287 on NVD →
Uploader [uploader] < 1.0.5 (closed)
unknown
WordPress Uploader plugin is prone to an arbitrary file upload vulnerability because of failure of adequately validate files before uploading them. This vulnerability allows an attacker to upload arbitrary files to the affected computer.
Update the plugin.
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Jan 3, 2013
Uploader [uploader] < 1.0.1 (closed)
unknown
This WordPress Uploader plugin's "num" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentica...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Jan 24, 2011
Uploader [uploader] <= 1.0.4 (unfixed + closed)
unknown
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
Uploader [uploader] <= 1.0.4 (unfixed + closed)
unknown
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database