CVE-2014-5014: Tinywebgallery WordPress Flash Uploader

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.

Affected products

  • Tinywebgallery WordPress Flash Uploader: before 3.1.3 (fixed in 3.1.3)

Published 2018-04-25. Last modified 2026-06-17.