The Power Zoomer plugin for WordPress is a software tool that websites can use to upload images and other files. Unfortunately, versions of this plugin up to and including 1.2 are vulnerable to an attack in which someone can upload an arbitrary file to the website’s server without being authenticated. This could potentially allow malicious code to be executed on the server, compromising the website.