Dendelion < 2.6.6 - Arbitrary File Upload
criticalThe Dendelion theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload-handler.php file in versions before 2.6.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possibl...
- CVSS:
- 9.8
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.6
- Disclosed:
- Jan 31, 2014