Elemin < 1.4.3 - Arbitrary File Upload
criticalElemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
- CVSS:
- 9.8
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Nov 13, 2013