CVE-2015-9479: Malicious File Upload
Published Oct 10, 2019
·Updated
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
Affected Software
1 affected component
Advancedcustomfields Acf Fronted Display Wordpress<=2015-07-03
Event History
Oct 10, 2019
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2015-9479.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an ac…'
3
What is the severity of CVE-2015-9479?
The severity of CVE-2015-9479 is critical.
4
How does CVE-2015-9479 affect the affected software?
CVE-2015-9479 affects the ACF-Frontend-Display plugin for WordPress through 2015-07-03.
5
How can CVE-2015-9479 be fixed?
To fix CVE-2015-9479, update the ACF-Frontend-Display plugin to a version after 2015-07-03.