plugin

Memphis Documents Library Vulnerabilities

10 known security issues reported for the Memphis Documents Library WordPress plugin. Most recent disclosed Aug 22, 2019.

2 critical 1 high 1 medium

Running Memphis Documents Library on your site? Check whether your installed version is affected.

Scan your site free

Memphis Documents Library [memphis-documents-library] < 3.0 (closed)

unknown

[en] The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Aug 22, 2019

CVE-2014-10383 on NVD →

Memphis Documents Library [memphis-documents-library] < 3.0 (closed)

unknown

[en] The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Aug 22, 2019

CVE-2014-10384 on NVD →

Memphis Documents Library [memphis-documents-library] < 3.0 (closed)

unknown

[en] The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Aug 22, 2019

CVE-2014-10385 on NVD →

Memphis Documents Library <= 3.1.5 - Arbitrary File Download

high

The Memphis Documents Library plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including 3.1.5 via the 'mdocs-img-preview' parameter. This makes it possible for unauthenticated users to access and download arbitrary files on the server such as the wp-config.php file which can reveal...

CVSS:
7.5
Affected:
up to 3.1.5
Fixed in:
3.1.6
Disclosed:
Mar 22, 2016

Memphis Documents Library [memphis-documents-library] < 3.1.6 (closed)

unknown

Memphis Document Library plugin is prone to an arbitrary file download vulnerability. It allows an attacker to download arbitrary files from the web server and get potentially sensitive information. Update the plugin.

Affected:
up to 3.1.6
Fixed in:
3.1.6
Disclosed:
Mar 22, 2016

Memphis Documents Library [memphis-documents-library] < 3.1.6

unknown

The Memphis Documents Library plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including 3.1.5 via the 'mdocs-img-preview' parameter. This makes it possible for unauthenticated users to access and download arbitrary files on the server such as the wp-config.php file which can reveal...

Affected:
up to 3.1.6
Fixed in:
3.1.6
Disclosed:
Mar 22, 2016

Memphis Documents Library <= 2.6.16 - Local File Inclusion

critical

The Memphis Documents Library plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.16. This allows unauthorized attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...

CVSS:
9.8
Affected:
up to 2.6.16
Fixed in:
3.0
Disclosed:
Sep 4, 2015

CVE-2014-10384 on NVD →

Memphis Documents Library <= 2.6.16 - Remote File Inclusion

critical

The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.

CVSS:
9.8
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Sep 4, 2015

CVE-2014-10383 on NVD →

Memphis Documents Library <= 2.6.16 - Cross-Site Scripting

medium

The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.

CVSS:
6.1
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Aug 21, 2014

CVE-2014-10385 on NVD →

Memphis Documents Library [memphis-documents-library] < 3.1.6

unknown

The function &quot;mdocs_img_preview&quot; is in charge of downloading image previews previously uploaded by the administrator, but it does not sanitize the file path being downloaded, thus, allowing to download arbitrary files in the file system. The vulnerable GET parameter is &quot;mdocs-img-preview&quot;. The...

Affected:
up to 3.1.6
Fixed in:
3.1.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database