CVE-2011-3129

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
10/08/2011
Last modified:
11/04/2025

Description

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:3.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.2:beta1:*:*:*:*:*:*