plugin

Cimy User Manager Vulnerabilities

1 known security issue reported for the Cimy User Manager WordPress plugin. Most recent disclosed Oct 24, 2012.

1 high

Running Cimy User Manager on your site? Check whether your installed version is affected.

Scan your site free

Cimy User Manager < 1.4.4 - Arbitrary File Read

high

The Cimy User Manager plugin for WordPress is vulnerable to Directory Traversal in versions before 1.4.4 via the 'cimy_um_filename' parameter. This allows attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Oct 24, 2012

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database