ionCube tester plus - Arbitrary File Download vulnerability
highArbitrary File Download vulnerability
- CVSS:
- 7.5
- Affected:
- up to 1.3
- Fixed in:
- 1.4
- Disclosed:
- Mar 4, 2026
plugin
2 known security issues reported for the Ioncube Tester Plus WordPress plugin. Most recent disclosed Mar 4, 2026.
Running Ioncube Tester Plus on your site? Check whether your installed version is affected.
Scan your site freeArbitrary File Download vulnerability
The ionCube Tester Plus plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free