The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/e709958c-7bce-45d7-9a0a-6e0ed12cd03f | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2022-08-01 06:15
Updated : 2022-08-04 11:47
NVD link : CVE-2022-1585
Mitre link : CVE-2022-1585
JSON object : View
CWE
                
                    
                        
                        CWE-552
                        
            Files or Directories Accessible to External Parties
Products Affected
                project-source-code-download_project
- project-source-code-download


