Cross-RSS <= 1.7 - Path Traversal
highAbsolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php.
- CVSS:
- 7.5
- Affected:
- up to 1.7
- Fix:
- No patched version reported
- Disclosed:
- May 29, 2014