The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://wordpress.org/plugins/wp-file-upload/#developers | release notes |