Input validation vulnerability in Work The Flow File Upload 2.5.2

The Work The Flow File Upload plugin for WordPress has a security issue that can allow unauthenticated attackers to upload malicious files to the affected website’s server. This vulnerability affects versions up to, and including, 2.5.2, and exists due to the lack of file type validation in the jQuery-File-Upload-9.5.0 server and test files. If exploited, this could lead to remote code execution.

Detected in:

Work The Flow File Upload open vulnerable versions: >= * <= 2.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.