Input validation vulnerability in Fusion Engage 1.0.5

The Fusion Engage plugin for WordPress has a security vulnerability which allows unauthenticated attackers to include and execute any file type on the server. This vulnerability affects all versions up to 1.0.5 and can be exploited through the ‘video’ parameter. With this vulnerability, attackers can bypass access controls, obtain sensitive data, or even execute code stored in files.

Detected in:

Fusion Engage open vulnerable versions: >= * <= 1.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.