{"id":5607623,"date":"2014-12-24T02:44:42","date_gmt":"2014-12-24T02:44:42","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/upload-exploit\/"},"modified":"2016-08-22T13:48:56","modified_gmt":"2016-08-22T13:48:56","slug":"upload-exploit","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/upload-exploit\/","title":{"rendered":"Upload Exploit"},"content":{"rendered":"<p>Hello, my site has been today hacked and compromised!<\/p>\n<p>Problem is in <strong>\/wp-content\/plugins\/wp-symposium\/server\/php\/index.php<\/strong> -&gt; <strong>\/wp-content\/plugins\/wp-symposium\/server\/php\/UploadHandler.php<\/strong><\/p>\n<p><strong>class UploadHandler<\/strong> is not protected and <strong>\/wp-content\/plugins\/wp-symposium\/server\/php\/UploadHandler.php<\/strong> allow any extension!<\/p>\n<p>On my website has been uploaded encoded .php files for sending spam and many more \ud83d\ude41<\/p>\n<p>https:\/\/wordpress.org\/plugins\/wp-symposium\/<\/p>\n","protected":false},"template":"","class_list":["post-5607623","topic","type-topic","status-closed","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/5607623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/5607623\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=5607623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}