CVE-2012-3578: Medium severity wordpress floating chat widget vulnerability
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3578?
CVE-2012-3578 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code on affected systems.
How do I fix CVE-2012-3578?
To fix CVE-2012-3578, update the FCChat Widget plugin to version 2.2.13.2 or later, which patches the vulnerability.
Which versions of the FCChat Widget are affected by CVE-2012-3578?
CVE-2012-3578 affects FCChat Widget versions 2.2.13.1 and earlier.
What types of files can be exploited in CVE-2012-3578?
CVE-2012-3578 can be exploited by uploading files with executable extensions followed by a safe extension.
Which WordPress installations are at risk from CVE-2012-3578?
Any WordPress site using the vulnerable FCChat Widget plugin version 2.2.13.1 or older is at risk from CVE-2012-3578.