File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
high
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbi...
- CVSS:
- 7.5
- Affected:
- up to 3.9.9.0.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 19, 2025
CVE-2025-2539 on NVD →
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated File Upload via upload Function
critical
The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's se...
- CVSS:
- 9.8
- Affected:
- up to 3.9.9.0.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 18, 2025
CVE-2025-2512 on NVD →
File Away <= 3.9.9.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The File Away plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.9.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- CVSS:
- 6.4
- Affected:
- up to 3.9.9.0.1
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2023
CVE-2023-0431 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database