Vulnerability Details: Arbitrary File Upload Vulnerability in ChikunCounter
One of the things we do to make sure our customers have the best data on vulnerabilities in WordPress plugins is to monitor third party data on hacking attempts. Through that we recently came across a request for a file, /wp-content/plugins/chikuncount/swfobject.js, from the plugin ChikunCounter. That plugin is no longer in the WordPress Plugin Directory, which could have been due to it being removed for a security issue.
Looking at the plugin it has a copy of the library Open Flash Charts, which was discovered to have an arbitrary file upload vulnerability in 2009. In the case of this plugin a new version was never released to fix the issue. [Read more]