CVE-2015-9272: Code Injection
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vwupload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9272?
CVE-2015-9272 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2015-9272?
To fix CVE-2015-9272, update the Videowhisper Video Presentation plugin to a patched version or remove it if it is not in use.
What software is affected by CVE-2015-9272?
CVE-2015-9272 affects Videowhisper Video Presentation plugin version 3.31.17 for WordPress.
Can CVE-2015-9272 be exploited remotely?
Yes, CVE-2015-9272 can be exploited by remote attackers to execute arbitrary code on the affected system.
What is the nature of the vulnerability in CVE-2015-9272?
CVE-2015-9272 allows the upload of files with deceptive extensions, such as .phtml, which can contain malicious PHP code.