Image Export [image-export] < 1.1.1
unknown
[en] Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- May 23, 2017
CVE-2015-5609 on NVD →
Image Export [image-export] < 1.1.1 (closed)
unknown
An attacker can access wp-config.php and get database credentials. Vulnerability exists in download.php file: localhost/wp/wp-content/plugins/image-export/download.php?file=../../../wp-config.php.
Upgrade the plugin.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Mar 21, 2016
Image Export < 1.1.1 - Path Traversal
critical
Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.
- CVSS:
- 9.1
- Affected:
- up to 1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Jul 1, 2015
CVE-2015-5609 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database