plugin

Correos Oficial Vulnerabilities

1 known security issue reported for the Correos Oficial WordPress plugin. Most recent disclosed Jan 31, 2023.

1 high

Running Correos Oficial on your site? Check whether your installed version is affected.

Scan your site free

Correos Oficial <= 1.3.0.0 - Unauthenticated Arbitrary File Download

high

The Correos Oficial plugin for WordPress is vulnerable to the unauthorized download of files in versions up to, and including, 1.3.0.0. This is due to insufficient validation on the supplied file path of a document being downloads. This makes it possible for unauthenticated attackers to download arbitrary files, such a...

CVSS:
7.5
Affected:
up to 1.3.0.0
Fix:
No patched version reported
Disclosed:
Jan 31, 2023

CVE-2023-0331 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database