CVE-2012-1125

Kish Guest Posting <1.2 - RCE

Title source: llm

Description

Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

Exploits (1)

exploitdb WORKING POC
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/18412

Scores

EPSS 0.3788
EPSS Percentile 97.2%

Details

Status published
Products (2)
kishore_asokan/kish_guest_posting_plugin 1.0
kishore_asokan/kish_guest_posting_plugin < 1.1
Published Oct 08, 2012
Tracked Since Feb 18, 2026