FREE DOWNLOAD MANAGER <= 1.0.0 - Unauthenticated Arbitrary File Download
highThe FREE DOWNLOAD MANAGER plugin for WordPress is vulnerable to Arbitrary File Downloads in all versions up to, and including, 1.0.0 via the download_stats_updated() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive informat...
- CVSS:
- 7.5
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 15, 2024