关键漏洞信息 标题 Uploadify <= 1.0 Unauthenticated Arbitrary File Upload 严重程度 Critical 日期 January 15, 2026 漏洞详情 CVE-2011-10041 CWE-434: Unrestricted Upload of File with Dangerous Type 影响范围 Uploadify <= 1.0 Description: This WP plugin is no longer available for download CVSS 4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 参考资料 Packet Storm Exploit WPScan Advisory w/ Exploitation Acknowledgment Wordfence Advisory Acunetix Advisory 描述 Description: Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution by uploading executable content to a web-accessible location. 发现者 Credit: b0telh0 from GotGeek Labs