In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2022-06-24T15:00:17

Updated: 2024-08-06T15:20:36.928Z

Reserved: 2013-02-19T00:00:00

Link: CVE-2013-1916

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-24T15:15:08.957

Modified: 2022-07-07T16:15:40.403

Link: CVE-2013-1916

cve-icon Redhat

No data.