8.8
CVSSv3

CVE-2013-1916

Published: 24/06/2022 Updated: 07/07/2022
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

user photo project user photo 0.9.4

Exploits

# Exploit Title: WordPress User Photo Component Remote File Upload Vulnerability # Google Dork: inurl:"/wp-content/uploads/userphoto/" # Date: 17/FEB/2011 # Author: ADVtools # Software Link: wordpressorg/extend/plugins/user-photo/ # Version: 094 # Tested on: *nix , Windows I Product Description User Photo is a WordPress component that ...