Vulnerabilities (CVE)

Filtered by vendor Estatik Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10959 1 Estatik 1 Estatik 2019-09-16 4.0 MEDIUM 6.5 MEDIUM
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.