Input validation vulnerability in Daily Deal by Templatic 2.2.4

The Daily Deal theme for WordPress is not secure in versions unknown. There is a missing feature that should check the type of file being uploaded to the website. Because this feature is missing, attackers who are not authenticated or not logged in can upload any type of file to the affected website’s server. This can enable the attacker to run remote code, which could be malicious.

Detected in:

Daily Deal by Templatic open vulnerable versions: >= * <= 2.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.