Description
WordPress Plugin Wp-FileManager is prone to a vulnerability that attackers can exploit to upload arbitrary PHP script code and execute it in the context of the webserver process. WordPress Plugin Wp-FileManager version 1.2 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
http://www.exploit-db.com/exploits/4844/
http://packetstormsecurity.com/files/view/62341/wpfile-upload.txt
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20415)
SugarCRM Other Vulnerability (CVE-2004-1225)
WordPress Plugin UserPro-Community and User Profile Privilege Escalation (4.9.20)
XOOPS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-12138)
Apache HTTP Server CVE-2009-1191 Vulnerability (CVE-2009-1191)