CVE-2016-15033 — The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2 — CVE Database · The Intelligence Room