GeoPlaces <= 4 - Arbitrary File Upload
criticalThe GeoPlaces 4 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /monetize/upload/ directory in versions up to, and including, 4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code...
- CVSS:
- 9.8
- Affected:
- up to 4beta
- Fixed in:
- 5
- Disclosed:
- Oct 24, 2013