WordPress Plugin Vulnerabilities

ThemeMakers Themes - Information Disclosure

Description

Multiple themes from ThemeMaker allow remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the /wp-content/uploads/tmm_db_migrate/wp_users.dat file

Affects Plugins

Fixed in 2.0

Affects Themes

Fixed in 1.0.3
Fixed in 1.1.9
Fixed in 1.1.1
Fixed in 1.1.2
Fixed in 1.1.3
No known fix
Fixed in 1.3.2.1
No known fix
No known fix
No known fix
No known fix
No known fix
Fixed in 1.1.8
No known fix

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Submitter
pvdl
Verified
No

Timeline

Publicly Published
2015-05-15 (about 10 years ago)
Added
2015-05-27 (about 10 years ago)
Last Updated
2020-12-09 (about 5 years ago)

Other