MAS Static Content <= 1.0.8 - Authenticated (Contributor+) Private Static Content Page Disclosure
mediumThe MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract potentially sensitive information from private static c...
- CVSS:
- 4.3
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.9
- Disclosed:
- Sep 24, 2024