CVE-2007-3543
Last modified
CVE-2007-3543 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.. EPSS estimates a 1.65% chance of exploitation in the next 30 days.
Description
Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | <= 2.2.0 |
| Wordpress | Wordpress Mu | <= 1.2.2 |
References
- http://secunia.com/advisories/25794Vendor Advisory
- http://secunia.com/advisories/25794Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3543?
How severe is CVE-2007-3543?
How do I fix CVE-2007-3543?
Are you affected by CVE-2007-3543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
