Various Orange themes (Various Unspecified Versions) - Cross-Site Request Forgery to Arbitrary File Upload
highVarious Orange themes for WordPress are vulnerable to arbitrary file uploads due to a Cross-Site Request Forgery vulnerability in the '/functions/upload-handler.php' file. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution po...
- CVSS:
- 8.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2013