File Download <= 1.4 - Open Proxy
highThe File Download plugin for WordPress has an Open Proxy vulnerability via the 'path' parameter in versions up to, and including, 1.4.
- CVSS:
- 8.2
- Affected:
- up to 1.4
- Fixed in:
- 2.0
- Disclosed:
- Mar 27, 2017
plugin
8 known security issues reported for the Filedownload WordPress plugin. Most recent disclosed Mar 27, 2017.
Running Filedownload on your site? Check whether your installed version is affected.
Scan your site freeThe File Download plugin for WordPress has an Open Proxy vulnerability via the 'path' parameter in versions up to, and including, 1.4.
[en] XSS in filedownload v1.4 wordpress plugin
[en] Open Proxy in filedownload v1.4 wordpress plugin
[en] Blind SQL Injection in filedownload v1.4 wordpress plugin
The filedownload plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing queries...
The filedownload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
TheCartPress plugin's "download.php" parameter is prone to remote file include vulnerability. It allows an attacker to include a remote file and get access to the server. It causes such problems as sensitive information disclosure, corss-site scripting attacks, code execution on the web server. Update the plugin.
The filedownload WordPress plugin was affected by a (download.php) Remote File Disclosure security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free