CVE-2012-6649
CRITICALCVSS 9.8/10EPSS 16.26%
Last modified
CVE-2012-6649 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.. EPSS estimates a 16.26% chance of exploitation in the next 30 days.
Description
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Devfarm | Wp Gpx Maps | 1.1.21 |
References
- https://www.openwall.com/lists/oss-security/2014/06/26/4Mailing List, Third Party Advisory
- https://www.securityfocus.com/bid/53909Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2014/06/26/4Mailing List, Third Party Advisory
- https://www.securityfocus.com/bid/53909Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6649?
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
How severe is CVE-2012-6649?
CVE-2012-6649 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 16.26% probability of exploitation in the next 30 days.
How do I fix CVE-2012-6649?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6643Multiple SQL injection vulnerabilities in the update_counter…
- CVE-2012-6644Multiple cross-site scripting (XSS) vulnerabilities in ClipB…
- CVE-2012-6645Cross-site scripting (XSS) vulnerability in the autocomplete…
- CVE-2012-6646F-Secure Anti-Virus, Safe Anywhere, and PSB Workstation Secu…
- CVE-2012-6647The futex_wait_requeue_pi function in kernel/futex.c in the …
- CVE-2012-6648gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and e…
- CVE-2012-6651Multiple directory traversal vulnerabilities in the Vitamin …
- CVE-2012-6652Directory traversal vulnerability in pageflipbook.php script…
- CVE-2012-6653Unspecified vulnerability in the All Video Gallery (all-vide…
- CVE-2012-6654Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and …
- CVE-2012-6655An issue exists AccountService 0.6.37 in the user_change_pas…3.3
- CVE-2012-6656iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 …
Are you affected by CVE-2012-6649?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
