CVE-2012-3577
Nmedia Member Conversation < 1.3 - Access Control
Title source: ruleDescription
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Sammy FORGIT · phpwebappsphp
https://www.exploit-db.com/exploits/37353
References (6)
Scores
EPSS
0.2707
EPSS Percentile
96.4%
Details
CWE
CWE-264
Status
published
Products (3)
nmedia/member_conversation
1.0
nmedia/member_conversation
1.2
nmedia/member_conversation
< 1.3
Published
Jun 17, 2012
Tracked Since
Feb 18, 2026