CVE-2015-9340 – WordPress File Upload < 3.0.0 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2015-9340
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files. El plugin wp-file-upload anterior de la versión 3.0.0 para WordPress tiene restricciones insuficientes en la carga de archivos php, js, pht, php3, php4, php5, phtml, htm, html y htacces • https://wordpress.org/plugins/wp-file-upload/#developers • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2015-9339 – WordPress File Upload < 2.7.1 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2015-9339
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. El plugin wp-file-upload anterior a la versión 2.7.1 para WordPress tiene restricciones insuficientes en la carga de archivos .js. • https://wordpress.org/plugins/wp-file-upload/#developers • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2015-9338 – WordPress File Upload <= 2.4.6 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2015-9338
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. El plugin wp-file-upload anterior a la versión 2.5.0 para WordPress tiene restricciones insuficientes en la carga de archivos .php. • https://wordpress.org/plugins/wp-file-upload/#developers • CWE-434: Unrestricted Upload of File with Dangerous Type •