Input validation vulnerability in Echelon *

The Echelon theme for WordPress has a security flaw that can be exploited by unauthenticated attackers. This flaw allows them to upload any file they choose to the server, which can be used to execute code remotely. This vulnerability exists in versions of the theme up to, and including, [up to affected version]. To fix this issue, the file type validation in the ~/lib/admin/functions/media-upload.php file should be checked and improved.

Detected in:

Echelon fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.