Description
WordPress Plugin FoxyPress is prone to multiple SQL injection, arbitrary file upload, cross-site scripting and cross-site request forgery vulnerabilities. A successful exploit may allow an attacker to gain unauthorized access and perform certain administrative actions, compromise the application, disclose potentially sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin FoxyPress version 0.4.2.5 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 0.4.2.9 or latest
References
http://www.securityfocus.com/bid/56332/exploit
http://www.waraxe.us/advisory-95.html
http://www.exploit-db.com/exploits/22374/
http://packetstormsecurity.com/files/117768/WordPress-FoxyPress-0.4.2.5-XSS-CSRF-SQL-Injection.html
Related Vulnerabilities
WordPress Plugin Memphis Documents Library Cross-Site Request Forgery (3.9.20)
WordPress Plugin Login with Cognito Cross-Site Scripting (1.4.8)
WordPress Plugin File Gallery Remote Code Execution (1.7.9)
Oracle Database Server CVE-2011-0852 Vulnerability (CVE-2011-0852)
TYPO3 Improper Input Validation Vulnerability (CVE-2013-4250)