CVE-2017-16871: Code Injection
DISPUTED The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the pluploadaction function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16871?
CVE-2017-16871 has a severity rating that indicates it may lead to remote PHP code execution.
How do I fix CVE-2017-16871?
To fix CVE-2017-16871, ensure you update the UpdraftPlus plugin to a version newer than 1.13.12.
What software is affected by CVE-2017-16871?
CVE-2017-16871 affects the UpdraftPlus plugin for WordPress versions up to 1.13.12.
What causes the vulnerability CVE-2017-16871?
CVE-2017-16871 is caused by a race condition in the plupload_action function prior to file deletion.
Is there a workaround for CVE-2017-16871?
A workaround for CVE-2017-16871 is to disable the UpdraftPlus plugin until it can be updated.