Home > Content Management, File Inclusion > WordPress Nmedia Member Conversation Plugin Arbitrary File Upload

WordPress Nmedia Member Conversation Plugin Arbitrary File Upload

June 30th, 2012

Application: WordPress
Affected Version: version 1.3 and other versions.
Vendor’s URL: Nmedia Member Conversation Plugin
Bug Type: File Upload
Risk Level: Critical

Solution:
Restrict access to the /wp-content/plugins/wordpress-member-private-conversation/doupload.php script (e.g. via .htaccess).

Content Management, File Inclusion

Comments are closed.