Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://wordpress.org/plugins/membership-simplified-for-oap-members-only | not applicable |
http://www.vapidlabs.com/advisory.php?v=187 | third party advisory exploit |
https://www.exploit-db.com/exploits/41622/ | third party advisory vdb entry exploit |
https://wpvulndb.com/vulnerabilities/8777 | third party advisory |