IDB Ecommerce (wpStoreCart 5) < 2.5.30 - Arbitrary File Upload
criticalUnrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart.
- CVSS:
- 9.8
- Affected:
- up to 2.5.29
- Fixed in:
- 2.5.30
- Disclosed:
- Mar 6, 2012