The Blaze Slideshow plugin for WordPress is vulnerable to a security risk in versions up to, and including, 2.4. This means that unauthenticated attackers are able to upload any type of file to the server of a affected website, which could lead to remote code execution. To fix the issue, the file type validation needs to be added to the “/js/swfupload/js/upload.php” file.