Arbitrary Directory Creation Vulnerability in Powerplay Gallery Plugin 3.3 for WordPress

Arbitrary Directory Creation Vulnerability in Powerplay Gallery Plugin 3.3 for WordPress

CVE-2015-5682 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.

Learn more about our Wordpress Pen Testing.