CVE-2016-10959: Malicious File Upload
Published Sep 16, 2019
·Updated
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via esmediaimages[] to wp-admin/admin-ajax.php.
Affected Software
1 affected component
Estatik Estatik Wordpress<2.3.1
Event History
Sep 16, 2019
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10959?
CVE-2016-10959 is rated as a medium severity vulnerability due to its potential for authenticated arbitrary file uploads.
2
How do I fix CVE-2016-10959?
To mitigate CVE-2016-10959, update the Estatik plugin to version 2.3.1 or later.
3
What impact does CVE-2016-10959 have on affected systems?
CVE-2016-10959 allows attackers to upload arbitrary files if they are authenticated, which could lead to remote code execution.
4
Which version of the Estatik plugin is affected by CVE-2016-10959?
CVE-2016-10959 affects all versions of the Estatik plugin prior to 2.3.1.
5
Is CVE-2016-10959 exploitable remotely?
CVE-2016-10959 requires authentication, making it necessary for an attacker to be logged in to exploit the vulnerability.