An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
{
"cpe": "cpe:2.3:a:textpattern:textpattern:4.8.8:-:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "4.8.8-NA"
}
]
}