
🚨 CVE-2016-15042: Frontend File Manager < 4.0 & N-... Unauthenticated arbitrary file upload in two WP plugins via AJAX endpoints offers trivial RCE path; missing file type v... https://zerodaysignal.com/vulnerability/CVE-2016-15042 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces a CVE-2016-15042 flaw that allows unauthenticated arbitrary file uploads in two WordPress plugins, enabling trivial remote code execution, and provides a link to further details.
