Flash Uploader <= 3.1.2 - Arbitrary Command Execution
criticalThe WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
- CVSS:
- 9.8
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jul 18, 2014