CVE-2014-5324: Code Injection
Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5324?
CVE-2014-5324 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary PHP code.
How do I fix CVE-2014-5324?
To fix CVE-2014-5324, upgrade the N-Media file uploader plugin to version 3.4 or later.
Who is affected by CVE-2014-5324?
CVE-2014-5324 affects remote authenticated users with Author privileges using vulnerable versions of the N-Media file uploader plugin.
What can attackers do with CVE-2014-5324?
Attackers can exploit CVE-2014-5324 to upload and execute arbitrary PHP code on affected WordPress sites.
Which versions of the N-Media file uploader are vulnerable to CVE-2014-5324?
Versions prior to 3.4, specifically from 3.0 to 3.3, of the N-Media file uploader plugin are vulnerable to CVE-2014-5324.