CVE-2012-3814: High severity Pippin Williamson Font Uploader vulnerability
Published Jun 27, 2012
·Updated
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.
Affected Software
2 affected components
Pippin Williamson Font Uploader=1.2.4
WordPress
Event History
Jun 27, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3814?
CVE-2012-3814 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2012-3814?
To fix CVE-2012-3814, upgrade the Font Uploader plugin to version 1.2.5 or later.
3
What systems are affected by CVE-2012-3814?
CVE-2012-3814 affects the Font Uploader plugin version 1.2.4 for WordPress.
4
What kind of attacks can exploit CVE-2012-3814?
Attackers can exploit CVE-2012-3814 by uploading specially crafted PHP files disguised with a .php.ttf extension.
5
Is CVE-2012-3814 an easily exploitable vulnerability?
Yes, CVE-2012-3814 is considered easily exploitable due to the lack of restrictions on file uploads.