Unrated severityNVD Advisory· Published Jun 17, 2012· Updated Apr 29, 2026
CVE-2012-3577
CVE-2012-3577
Description
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.
Affected products
3cpe:2.3:a:nmedia:member_conversation:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:nmedia:member_conversation:*:*:*:*:*:*:*:*range: <=1.3
- cpe:2.3:a:nmedia:member_conversation:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:nmedia:member_conversation:1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- packetstormsecurity.org/files/113287/WordPress-Nmedia-WP-Member-Conversation-1.35.0-Shell-Upload.htmlnvdExploit
- www.opensyscom.fr/Actualites/wordpress-plugins-nmedia-wordpress-member-conversation-shell-upload-vulnerability.htmlnvdExploit
- www.securityfocus.com/bid/53790nvdExploit
- secunia.com/advisories/49375nvdVendor Advisory
- wordpress.org/extend/plugins/wordpress-member-private-conversation/changelog/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/76076nvd
News mentions
0No linked articles in our index yet.