Input validation vulnerability in MediaPress 1.5.9.1

The MediaPress plugin for WordPress has a security issue in versions up to and including 1.5.9.1. This means that attackers who are logged in with at least contributor-level access can include and run any type of file on the server, which could contain harmful PHP code. This can be used to get around security measures, access private information, or run code in situations where seemingly harmless files like images can be uploaded and used.

Detected in:

MediaPress fixed vulnerable versions: >= * <= 1.5.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.