A vulnerability has been discovered in the SFBrowser plugin for WordPress, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to the wp-content/plugins/sfbrowser/connectors/php/sfbrowser.php script improperly validating uploaded files, which can be exploited to execute arbitrary PHP code by uploading a PHP file with an arbitrary appended file extension.
The vulnerability is confirmed in version 1.4.5. Other versions may also be affected.