The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/b125a765-a6b6-421b-bd8a-effec12bc629 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-11-28 06:15
Updated : 2022-11-30 07:15
NVD link : CVE-2021-25059
Mitre link : CVE-2021-25059
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
metagauss
- download_plugin