CVE-2015-10144: Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected sites server using a double extension which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-10144?
CVE-2015-10144 has a medium severity rating due to the potential for arbitrary file uploads by authenticated attackers.
How do I fix CVE-2015-10144?
To fix CVE-2015-10144, you should update the Responsive Thumbnail Slider plugin to version 1.0.2 or later.
Who is affected by CVE-2015-10144?
Authenticated users with subscriber-level access and above are affected by CVE-2015-10144.
What type of vulnerability is CVE-2015-10144?
CVE-2015-10144 is categorized as an arbitrary file upload vulnerability due to missing file type sanitization.
What versions of the Responsive Thumbnail Slider are vulnerable to CVE-2015-10144?
Versions of the Responsive Thumbnail Slider plugin up to and including 1.0.1 are vulnerable to CVE-2015-10144.