CVE-2012-3577

Nmedia Member Conversation < 1.3 - Access Control

Title source: rule

Description

Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sammy FORGIT · phpwebappsphp
https://www.exploit-db.com/exploits/37353

Scores

EPSS 0.2707
EPSS Percentile 96.4%

Details

CWE
CWE-264
Status published
Products (3)
nmedia/member_conversation 1.0
nmedia/member_conversation 1.2
nmedia/member_conversation < 1.3
Published Jun 17, 2012
Tracked Since Feb 18, 2026