WordPress · Wordpress Flash Uploader Plugin · CVE-2014-5014
**Name of the Vulnerable Software and Affected Versions**
WordPress Flash Uploader plugin versions prior to 3.1.3
**Description**
The issue allows remote attackers to execute arbitrary commands. This is related to invalid characters in the `image magic path`.
**Recommendations**
For WordPress Flash Uploader plugin versions prior to 3.1.3, update to version 3.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the `image magic path` configuration to minimize the risk of exploitation.