WordPress Plugin Vulnerabilities

WordPress Download Manager < 3.1.25 - Authenticated Directory Traversal

Description

Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension.

Proof of Concept

Affects Plugins

Fixed in 3.1.25

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE

Miscellaneous

Original Researcher
Ramuel Gall
Submitter
Ramuel Gall
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-07-29 (about 4 years ago)
Added
2021-07-29 (about 4 years ago)
Last Updated
2022-02-24 (about 4 years ago)

Other