First published: Thu Oct 10 2019(Updated: )
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <=2015-07-03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2015-9479.
The title of this vulnerability is 'The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an ac…'
The severity of CVE-2015-9479 is critical.
CVE-2015-9479 affects the ACF-Frontend-Display plugin for WordPress through 2015-07-03.
To fix CVE-2015-9479, update the ACF-Frontend-Display plugin to a version after 2015-07-03.