← back
CVE-2014-8739observed exploitation

CVE-2014-8739

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 92%
from disclosure to weapon0 days
Published on NVDFeb 8
1st PoCOct 25
metasploitOct 22
VulnCheckFeb 8
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.