The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.
#TECHNOLOGY

404 Media is a new independent media company founded by technology journalists Jason Koebler, Emanuel Maiberg, Samantha Cole, and Joseph Cox.

Now, next, and beyond. Tracking need-to-know trends at the intersection of business and technology.

MakeUseOf was founded in 2006 and acquired and owned by Valnet Inc. since 2020., MUO is one of the largest online technology publications that millions of readers every turn to every month for expert tech guidance. We also have hundreds of thousands of fans across social media on Instagram, Facebook, X (Twitter), and Pinterest.