Font <= 7.5 - Path Traversal
mediumAbsolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.
- CVSS:
- 4.9
- Affected:
- up to 7.5
- Fixed in:
- 7.5.1
- Disclosed:
- Oct 12, 2015