Unrated severityNVD Advisory· Published Jan 13, 2015· Updated May 6, 2026
CVE-2014-10021
CVE-2014-10021
Description
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in server/php/.
Affected products
1- cpe:2.3:a:wpsymposiumpro:wp_symposium:14.11:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/35543nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/71686nvdBroken Link
News mentions
0No linked articles in our index yet.