CVE Published: 24/06/2022 |
CVE Updated: 06/08/2024 |
CVE Year: 2013 Source: redhat |
Vendor: n/a |
Product: WordPress Plugin User Photo Status : PUBLISHED
CVE-2013-1916 Description
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.