Wordpress Alert: Unauthenticated arbitrary file upload
A public form accepts a file type or location it should reject. The uploaded file may expose users or, in some configurations, execute server code.
What it looks like
A public form accepts a file type or location it should reject.
Why it matters
The uploaded file may expose users or, in some configurations, execute server code.
What to check
Check upload permissions, file validation, storage location, and installed-plugin advisories.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP file upload guidance.
- Categories: WordPress
- Tags: #WordPress Security, #File Security