First published: Wed May 21 2008(Updated: )
Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2392 is considered a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2008-2392, update your WordPress installation to version 2.5.2 or later immediately.
CVE-2008-2392 affects remote authenticated administrators using WordPress version 2.5.1 or earlier.
CVE-2008-2392 is an unrestricted file upload vulnerability that allows for arbitrary PHP file execution.
With CVE-2008-2392, an attacker can upload malicious PHP files and execute them on the server.