iThemes2 < 1.4.3 - Arbitrary File Upload
criticalThe iThemes2 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the themify-ajax.php file in versions up to 1.4.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Nov 13, 2013