Easy Digital Downloads – Recent Purchases <= 1.0.2 - Unauthenticated Remote File Inclusion
criticalThe Easy Digital Downloads – Recent Purchases plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files hosted on external server,s allowing the execution of any PHP code in those f...
- CVSS:
- 9.8
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- May 27, 2024