Description
WordPress Plugin WP Symposium is prone to multiple vulnerabilities that lets attackers upload arbitrary files. An attacker can exploit these vulnerabilities to upload arbitrary PHP code and run it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. WordPress Plugin WP Symposium version 11.11.26 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 11.12.24 or latest
References
Related Vulnerabilities
WordPress 4.0.x Cross-Site Scripting Vulnerability (4.0 - 4.0.8)
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2015-2750)
WordPress 3.8.x Arbitrary File Deletion Vulnerability (3.8 - 3.8.26)
Oracle Database Server Other Vulnerability (CVE-2006-2081)
Oracle Database Server CVE-2009-1997 Vulnerability (CVE-2009-1997)