Ahime Image Printer <= 1.0.0 - Unauthenticated Arbitrary File Download
criticalThe Ahime Image Printer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.0 via the ahime_image_download_zip() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2024