Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
References
Configurations
History
No history.
Information
Published : 2015-05-28 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-4133
Mitre link : CVE-2015-4133
CVE.ORG link : CVE-2015-4133
JSON object : View
Products Affected
reflex_gallery_project
- reflex_gallery
CWE