Correos Oficial <= 1.3.0.0 - Unauthenticated Arbitrary File Download
highThe Correos Oficial plugin for WordPress is vulnerable to the unauthorized download of files in versions up to, and including, 1.3.0.0. This is due to insufficient validation on the supplied file path of a document being downloads. This makes it possible for unauthenticated attackers to download arbitrary files, such a...
- CVSS:
- 7.5
- Affected:
- up to 1.3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 31, 2023