CVE-2015-9338: Malicious File Upload
Published Aug 22, 2019
·Updated
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
Affected Software
1 affected component
Iptanus Wordpress File Upload Wordpress<2.5.0
Event History
Aug 22, 2019
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the wp-file-upload plugin?
The vulnerability ID for the wp-file-upload plugin is CVE-2015-9338.
2
What is the severity of CVE-2015-9338?
CVE-2015-9338 has a severity value of 7.5 (high).
3
What is the affected software for CVE-2015-9338?
The affected software for CVE-2015-9338 is the wp-file-upload plugin before version 2.5.0 for WordPress.
4
What is the description of CVE-2015-9338?
CVE-2015-9338 is a vulnerability in the wp-file-upload plugin that allows insufficient restrictions on the upload of .php files.
5
How can I fix CVE-2015-9338?
To fix CVE-2015-9338, update the wp-file-upload plugin to version 2.5.0 or later.