Memphis Documents Library [memphis-documents-library] < 3.0 (closed)
unknown[en] The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Aug 22, 2019
plugin
10 known security issues reported for the Memphis Documents Library WordPress plugin. Most recent disclosed Aug 22, 2019.
Running Memphis Documents Library on your site? Check whether your installed version is affected.
Scan your site free[en] The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
[en] The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
[en] The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
The Memphis Documents Library plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including 3.1.5 via the 'mdocs-img-preview' parameter. This makes it possible for unauthenticated users to access and download arbitrary files on the server such as the wp-config.php file which can reveal...
Memphis Document Library plugin is prone to an arbitrary file download vulnerability. It allows an attacker to download arbitrary files from the web server and get potentially sensitive information. Update the plugin.
The Memphis Documents Library plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including 3.1.5 via the 'mdocs-img-preview' parameter. This makes it possible for unauthenticated users to access and download arbitrary files on the server such as the wp-config.php file which can reveal...
The Memphis Documents Library plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.16. This allows unauthorized attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
The function "mdocs_img_preview" is in charge of downloading image previews previously uploaded by the administrator, but it does not sanitize the file path being downloaded, thus, allowing to download arbitrary files in the file system. The vulnerable GET parameter is "mdocs-img-preview". The...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free