plugin

Multi Plugin Installer Vulnerabilities

4 known security issues reported for the Multi Plugin Installer WordPress plugin. Most recent disclosed Aug 24, 2015.

1 high

Running Multi Plugin Installer on your site? Check whether your installed version is affected.

Scan your site free

Multi Plugin Installer < 1.2.0 - Arbitrary File Read

high

The Multi Plugin Installer plugin for WordPress is vulnerable to Arbitrary File Read in versions before 1.2.0. This is due to vulnerable parameters 'filepath' and 'filename' in the mpi_download_file function. This makes it possible for unauthenticated attackers to read arbitrary files.

CVSS:
7.5
Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Aug 24, 2015

Multi Plugin Installer [multi-plugin-installer] < 1.2.0 (closed)

unknown

Because of this vulnerability, unauthenticated attackers can read arbitrary files. Update the plugin.

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Aug 24, 2015

Multi Plugin Installer [multi-plugin-installer] < 1.2.0

unknown

The Multi Plugin Installer plugin for WordPress is vulnerable to Arbitrary File Read in versions before 1.2.0. This is due to vulnerable parameters 'filepath' and 'filename' in the mpi_download_file function. This makes it possible for unauthenticated attackers to read arbitrary files.

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Aug 24, 2015

Multi Plugin Installer [multi-plugin-installer] < 1.2.0 (closed)

unknown

The multi-plugin-installer WordPress plugin was affected by an Unauthenticated File Traversal security vulnerability.

Affected:
up to 1.2.0
Fixed in:
1.2.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database