Input validation vulnerability in 360 Product Rotation 1.2.0

The 360 Product Rotation plugin for WordPress is vulnerable to malicious files being uploaded by unauthenticated attackers. This plugin has a feature that, in versions up to and including 1.2.0, allows for arbitrary file uploads without any type of validation. This means that an attacker can upload malicious files to the server, which in turn can lead to remote code execution.

Detected in:

360 Product Rotation open vulnerable versions: >= * <= 1.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.