Description
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/28452
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87384
Exploit x_refsource_misc
http://packetstormsecurity.com/files/123349
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/28452
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/97662
Scores
EPSS
0.0698
EPSS Percentile
91.5%
Details
Status
published
Products (1)
danny_morris/lazy_seo
1.1.9
Published
Sep 30, 2013
Tracked Since
Feb 18, 2026