plugin

Miwoftp Vulnerabilities

14 known security issues reported for the Miwoftp WordPress plugin. Most recent disclosed Apr 21, 2015.

3 high

Running Miwoftp on your site? Check whether your installed version is affected.

Scan your site free

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)

unknown

Miwo FTP plugin is prone to an arbitrary file download vulnerability. It allows an attacker to download arbitrary files from the web server and get potentially sensitive information. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 21, 2015

MiwoFTP < 1.0.6 - Cross-Site Request Forgery to Arbitrary File Deletion

high

The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to delete arbitrary files via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS:
8.8
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 15, 2015

MiwoFTP < 1.0.6 - Cross-Site Request Forgery leading to Remote Code Execution

high

The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.6. This makes it possible for unauthenticated attackers to upload arbitrary code and execute them via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS:
8.8
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 15, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)

unknown

Miwo FTP plugin is prone to an arbitrary file download vulnerability. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 15, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6

unknown

The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to delete arbitrary files via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 15, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6

unknown

The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.6. This makes it possible for unauthenticated attackers to upload arbitrary code and execute them via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 15, 2015

MiwoFTP < 1.0.5 - Arbitrary File Download

high

The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the improper use of a hook which utilizes a download file function. This makes it possible for unauthenticated attackers to arbitrarily download files located within the home directory of the affected site...

CVSS:
8.6
Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Apr 14, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)

unknown

Miwo FTP plugin's "post" parameter is prone to CSRF Arbitrary File Deletion Exploit vulnerability. Because of "seselitems[]" parameter is not properly sanitised, the files can be deleted with the permissions of the web server. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 14, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)

unknown

This Miwo FTP plugin is prone to a cross-site request forgery vulnerability. This vulnerability allows an attacker to execute certain actions via HTTP requests, such as PHP script file uploading with administrative privileges. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 14, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)

unknown

These vulnerabilities allow an attacker to execute certain actions via HTTP requests and in that way perform others actions with administrative privileges. Also, "get" and "post" parameters are not properly sanitised and it can be used to execute arbitrary HTML code in a user's browser session in context of an affected...

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 14, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.5

unknown

The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the improper use of a hook which utilizes a download file function. This makes it possible for unauthenticated attackers to arbitrarily download files located within the home directory of the affected site...

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Apr 14, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.5 (closed)

unknown

Because of this vulnerability, users can download a file within the scope of the home directory of the site. Update this plugin.

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Mar 16, 2015

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)

unknown

The miwoftp WordPress plugin was affected by a File &amp; Folder Manager &lt;= 1.0.5 - Multiple Vulnerabilities security vulnerability.

Affected:
up to 1.0.6
Fixed in:
1.0.6

MiwoFTP – File & Folder Manager [miwoftp] < 1.0.5 (closed)

unknown

A hook is added to &lsquo;init&rsquo; in the file &lsquo;miwoftp/miwoftp.php&rsquo;. This hook is triggered whenever a user visits the front end of the site. The function specified in this hook will proceed to allow the user to download a file within the scope of the home directory of the site. Various values from the...

Affected:
up to 1.0.5
Fixed in:
1.0.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database