MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)
unknown
Miwo FTP plugin is prone to an arbitrary file download vulnerability. It allows an attacker to download arbitrary files from the web server and get potentially sensitive information.
Update the plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 21, 2015
MiwoFTP < 1.0.6 - Cross-Site Request Forgery to Arbitrary File Deletion
high
The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to delete arbitrary files via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 15, 2015
MiwoFTP < 1.0.6 - Cross-Site Request Forgery leading to Remote Code Execution
high
The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.6. This makes it possible for unauthenticated attackers to upload arbitrary code and execute them via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 15, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)
unknown
Miwo FTP plugin is prone to an arbitrary file download vulnerability.
Update the plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 15, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6
unknown
The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to delete arbitrary files via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 15, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6
unknown
The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.6. This makes it possible for unauthenticated attackers to upload arbitrary code and execute them via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 15, 2015
MiwoFTP < 1.0.5 - Arbitrary File Download
high
The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the improper use of a hook which utilizes a download file function. This makes it possible for unauthenticated attackers to arbitrarily download files located within the home directory of the affected site...
- CVSS:
- 8.6
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Apr 14, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)
unknown
Miwo FTP plugin's "post" parameter is prone to CSRF Arbitrary File Deletion Exploit vulnerability. Because of "seselitems[]" parameter is not properly sanitised, the files can be deleted with the permissions of the web server.
Update the plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 14, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)
unknown
This Miwo FTP plugin is prone to a cross-site request forgery vulnerability. This vulnerability allows an attacker to execute certain actions via HTTP requests, such as PHP script file uploading with administrative privileges.
Update the plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 14, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)
unknown
These vulnerabilities allow an attacker to execute certain actions via HTTP requests and in that way perform others actions with administrative privileges. Also, "get" and "post" parameters are not properly sanitised and it can be used to execute arbitrary HTML code in a user's browser session in context of an affected...
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 14, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.5
unknown
The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the improper use of a hook which utilizes a download file function. This makes it possible for unauthenticated attackers to arbitrarily download files located within the home directory of the affected site...
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Apr 14, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.5 (closed)
unknown
Because of this vulnerability, users can download a file within the scope of the home directory of the site.
Update this plugin.
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Mar 16, 2015
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.6 (closed)
unknown
The miwoftp WordPress plugin was affected by a File & Folder Manager <= 1.0.5 - Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
MiwoFTP – File & Folder Manager [miwoftp] < 1.0.5 (closed)
unknown
A hook is added to ‘init’ in the file ‘miwoftp/miwoftp.php’. This hook is triggered whenever a user visits the front end of the site. The function specified in this hook will proceed to allow the user to download a file within the scope of the home directory of the site. Various values from the...
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database