Title:Remote file upload Vulnerability in Wordpress plugin csv2wpec-coupon v1.1
The code in csv2wpecCoupon_FileUpload.php does not properly sanitize user input, it checks the file mime-type for type x-php but this can be tricked when using the short code for