WordPress Cherry < 1.2.7 - Unauthenticated Arbitrary File Upload and Download
WordPress plugin Cherry < 1.2.7 has a vulnerability which enables an attacker to upload files directly to the server. This could result in attacker uploading backdoor shell scripts or downloading the wp-config.php file.
CVSS8.6