Description
PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
Affected products
- alanft / Relocate Upload0.14
- alanft / Relocate Upload0.10 – 0.10
- alanft / Relocate Upload0.11 – 0.11