CVE Database
/

CVE-2013-1916

Back to search

CVE-2013-1916

Published: Jun 24, 2022

Modified: Aug 6, 2024

PUBLISHED

Description

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

VendorProductVersions

n/a

WordPress Plugin User Photo

affected
WordPress Plugin User Photo 0.9.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now