diff --git a/WordPress-3.5-Issues.md b/WordPress-3.5-Issues.md index 7b8c087..932c6b2 100644 --- a/WordPress-3.5-Issues.md +++ b/WordPress-3.5-Issues.md @@ -26,7 +26,9 @@ Proof of Concept: ```[embed]javascript:alert(document.cookie)[/embed]``` ## Issue 3 -This issue was successfully investigated by [@erwan_lr](https://twitter.com/@erwan_lr), a WPScan Team member. "[Plupload] Allows you to upload files using HTML5 Gears, Silverlight, Flash, BrowserPlus or normal forms, providing some unique features such as upload progress, image resizing and chunked uploads." [2] +This issue was successfully investigated by [@erwan_lr](https://twitter.com/@erwan_lr), a WPScan Team member. "[Plupload] Allows you to upload files using HTML5 Gears, Silverlight, Flash, BrowserPlus or normal forms, providing some unique features such as upload progress, image resizing and chunked uploads." [2] + +The vulnerable file is included in WordPress versions 3.5, 3.4.2, 3.4.1, 3.4, 3.3.3 and 3.3.2. Proof of Concept: ```wp-includes/js/plupload/plupload.flash.swf?id=\"));}catch(e){alert(1);}//```