rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload
2016-12-21 00:00
James GolovichStrategic Overview
StatusPatched in 4.2.1
Affected PluginrtMedia for WordPress, BuddyPress and bbPress
Affected Version
< 4.2.1CVSS9.8Critical
CVE
N/AVulnerability Overview
The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, and including, 4.2. This is due to the 'rtUploadAttachment.php' file preventing direct access to the the file. This makes it possible for unauthenticated attackers to access the file directly which triggers execution and lets unauthenticated users upload files.
Technical Analysis
REMEDIATION: Update to version 4.2.1, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C