peter bassill · operator
$ cve CVE-2014-1905 JSON

CVE-2014-1905 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins/videowhisper-live-streaming-integration/ls/snapshots/ pathname, as demonstrated by a .php.jpg filename.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS9.79% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploityes
Published2014-12-29
Last modified2026-06-17

Affected (1)

VendorProduct
videowhispervideowhisper live streaming integration

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD