CVE-2019-9618 | GraceMedia Media Player Plugin up to 1.0 on WordPress ajax_controller.php cfg command injection (EDB-46537)
A vulnerability was found in GraceMedia Media Player Plugin up to 1.0 on WordPress. It has been declared as critical. The affected element is an unknown function of the file /gracemedia-media-player/templates/files/ajax_controller.php. Executing manipulation of the argument cfg can lead to command injection.
This vulnerability is registered as CVE-2019-9618. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is suggested to use an alternative component instead of the affected one.