CVE-2007-3543

Source
https://cve.org/CVERecord?id=CVE-2007-3543
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-3543.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-3543
Downstream
Published
2007-07-03T20:30:00Z
Modified
2026-04-10T03:38:57.701446Z
Summary
[none]
Details

Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the wpattachedfile metadata field; and then sending this file's content, along with its postID value, to (1) wp-app.php or (2) app.php.

References

Affected packages