MP3 Sticky Player <= 8.0 - Unauthenticated Arbitrary File Read/Download
highThe MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note...
- CVSS:
- 7.5
- Affected:
- up to 8.0
- Fixed in:
- 8.0
- Disclosed:
- Nov 22, 2024