Tag
The LightSync Pro plugin for WordPress, in versions up to and including 2.1.6, contains an arbitrary file upload vulnerability via the rest_replace_media() function, enabling authenticated attackers to achieve remote code execution.