CVE-2014-5324

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
26/09/2014
Last modified:
12/04/2025

Description

Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:najeebmedia:n-media_file_uploader:*:*:*:*:*:wordpress:*:* 3.3 (including)
cpe:2.3:a:najeebmedia:n-media_file_uploader:3.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:najeebmedia:n-media_file_uploader:3.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:najeebmedia:n-media_file_uploader:3.2:*:*:*:*:wordpress:*:*