belingoGeo <= 1.12.0 - Unauthenticated Arbitrary File Download
highThe belingoGeo plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.0 via the belingogeo_download_example() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 1.12.0
- Fixed in:
- 1.12.1
- Disclosed:
- May 9, 2025