PT-2013-6274 · WordPress · Optimizepress
Kurt Seifried
·
Published
2013-12-23
·
Updated
2013-12-24
·
CVE-2013-7102
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OptimizePress theme versions prior to 1.61
Description
The issue concerns unrestricted file upload vulnerabilities in multiple files within the OptimizePress theme for WordPress. These vulnerabilities allow remote attackers to execute arbitrary code by uploading a file with an executable extension and then accessing it directly. This has been exploited in the wild.
Recommendations
For versions prior to 1.61, update to version 1.61 or later to resolve the issue. As a temporary workaround, consider restricting access to the
media-upload.php, media-upload-lncthumb.php, and media-upload-sq button.php files in lib/admin/ to minimize the risk of exploitation. Additionally, restrict uploads to only necessary file types and ensure proper validation and sanitization of uploaded files.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Optimizepress