Input validation vulnerability in Annonces 1.2.0.1

The Annonces plugin for WordPress is vulnerable to a security risk in some versions. In versions up to and including 1.2.0.1, there is missing file type validation in a file called ‘theme.php’. This means that people who do not have permission to access the website can upload files to the website’s server. If these files are malicious, it can allow the attacker to run code on the website remotely.

Detected in:

Annonces fixed vulnerable versions: >= * <= 1.2.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.