Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter
highThe Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful explo...
- CVSS:
- 7.5
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Aug 26, 2026