First published: Tue Jul 03 2007(Updated: )
Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=2.2.0 | |
WordPress | <=1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3544 has a critical severity level due to the potential for arbitrary code execution on vulnerable WordPress sites.
To fix CVE-2007-3544, you should upgrade WordPress to version 2.2.1 or later and ensure all plugins are updated.
CVE-2007-3544 affects WordPress versions up to 2.2.0 and WordPress MU versions up to 1.2.2.
Yes, CVE-2007-3544 can be exploited remotely by authenticated users to upload and execute malicious PHP code.
Authenticated users with upload privileges on affected WordPress versions are at risk from CVE-2007-3544.