CVE-2009-3890 describes an unrestricted file upload vulnerability in WordPress versions prior to 2.8.6. This flaw, residing in the wp_check_filetype function, allows authenticated users to upload arbitrary code by using multiple-extension filenames (e.g., .php.jpg) when a specific Apache mod_mime configuration is enabled. The vulnerability carries a CVSS score of 6.0, indicating a medium severity. It requires authentication and moderate attack complexity, but successful exploitation could lead to partial compromise of confidentiality, integrity, and availability due to arbitrary code execution. While not listed on CISA's KEV catalog or showing active community discussion or media coverage, exploit code for this vulnerability is publicly available on ExploitDB, suggesting it could be exploited by determined attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.5CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.