EUCookieLaw <= 2.7.2 - Unauthenticated Arbitrary File Read
mediumThe EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerabili...
- CVSS:
- 5.9
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- May 8, 2025