CVE-2017-16949 | AccessKeys AccessPress Anonymous Post Pro Plugin up to 3.1.9 on WordPress file-uploader.php unrestricted upload (File 145398/Acc / EDB-43324)
A vulnerability was found in AccessKeys AccessPress Anonymous Post Pro Plugin up to 3.1.9 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/cores/file-uploader.php. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2017-16949. The attack can be launched remotely. Furthermore, there is an exploit available.