Vulnerabilities > Zingiri > Theme Tuner Plugin > 0.3

DATE CVE VULNERABILITY TITLE RISK
2012-01-29 CVE-2012-0934 Code Injection vulnerability in Zingiri Theme Tuner Plugin
PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parameter.
network
low complexity
zingiri wordpress CWE-94
7.5