Media File Manager Advanced <= 1.1.5 - Improper Access Control
highThe Media File Manager Advanced plugin for WordPress is vulnerable to Local File Disclosure, SQL Injection, Cross-Site Scripting, Site Ruining, and Changing of Content in versions up to, and including, 1.1.5. This is due to missing capability checks and insufficient input validation. This makes it possible for authenti...
- CVSS:
- 8.8
- Affected:
- up to 1.1.5
- Fix:
- No patched version reported
- Disclosed:
- May 14, 2012