WordPress Plugin Vulnerabilities

BookingPress < 1.1.23 - Unauthenticated Export File Download

Description

The plugin export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Submitter
Thanh Hang
Verified
Yes

Timeline

Publicly Published
2024-12-23 (about 1 year ago)
Added
2024-12-23 (about 1 year ago)
Last Updated
2024-12-23 (about 1 year ago)

Other