Input validation vulnerability in iThemes2 1.4.3

The iThemes2 Theme for WordPress is a vulnerable theme in versions up to 1.4.3. This means that unauthenticated attackers can upload arbitrary files to the affected website’s server. If they do, it could allow them to run code on the website remotely, which is a serious security risk. It is vulnerable because the themify-ajax.php file does not validate the types of files that can be uploaded.

Detected in:

iThemes2 fixed vulnerable versions: >= * < 1.4.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.