The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/42499b84-684e-42e1-b7f0-de206d4da553 | third party advisory exploit |