Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php,...
Vulnerability Description
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images_comingsoon, images_lncthumbs, or images_optbuttons in wp-content/uploads/optpress/, as exploited in the wild in November 2013.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-7102
Credits & Attribution
No credits recorded in the NVD database.
References
- http://help.optimizepress.com/customer/portal/articles/1381790-important-optimizepress-1-0-security-update
- http://www.osirt.com/2013/11/wordpress-optimizepress-hack-file-upload-vulnerability/
- http://blog.sucuri.net/2013/12/wordpress-optimizepress-theme-file-upload-vulnerability.html
- http://seclists.org/fulldisclosure/2013/Dec/127
Affected Vendor
optimizepress
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.