WP-lightpop <= 0.8.5.6 - Remote Media File Inclusion
criticalThe WP-lightpop plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including, 0.8.5.6 via the mediaplayer.swf file. This allows unauthenticated attackers to include remote files on the server.
- CVSS:
- 9.8
- Affected:
- up to 0.8.5.6
- Fix:
- No patched version reported
- Disclosed:
- May 25, 2014