Web3Press <= 3.2.0 - Authenticated (Contributor+) Arbitrary File Read
mediumThe Web3Press – Decentralize Publishing with Writing NFT plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can co...
- CVSS:
- 6.5
- Affected:
- up to 3.2.0
- Fixed in:
- 3.3.0
- Disclosed:
- May 2, 2025