peter bassill · operator
$ cve CVE-2012-1011 JSON

CVE-2012-1011 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9% (pctl 95)

Patch early

A public exploit exists.

Description

actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.04% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2012-02-07
Last modified2026-06-16

Affected (2)

VendorProduct
liknoallwebmenus plugin
wordpresswordpress

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD