First published: Thu Aug 22 2019(Updated: )
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Iptanus WordPress File Upload | <2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the wp-file-upload plugin is CVE-2015-9339.
The severity of CVE-2015-9339 is high with a severity value of 7.5.
The affected software for CVE-2015-9339 is the wp-file-upload plugin before version 2.7.1 for WordPress.
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
You can find more information about the wp-file-upload plugin on the WordPress plugin directory.
The CWE ID for CVE-2015-9339 is 434.