
🚨 CVE-2015-10138: Work The Flow File Upload <= 2.5... Missing file type validation in Work The Flow's jQuery-File-Upload opens WordPress sites to unauthenticated RCE - trivi... https://zerodaysignal.com/vulnerability/CVE-2015-10138 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet discloses CVE‑2015‑10138, noting that missing file type validation in Work The Flow's jQuery‑File‑Upload allows unauthenticated remote code execution on WordPress sites, with no PoC, exploit code, or active exploitation mentioned.
