Multi Plugin Installer < 1.2.0 - Arbitrary File Read
high
The Multi Plugin Installer plugin for WordPress is vulnerable to Arbitrary File Read in versions before 1.2.0. This is due to vulnerable parameters 'filepath' and 'filename' in the mpi_download_file function. This makes it possible for unauthenticated attackers to read arbitrary files.
- CVSS:
- 7.5
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 24, 2015
Multi Plugin Installer [multi-plugin-installer] < 1.2.0 (closed)
unknown
Because of this vulnerability, unauthenticated attackers can read arbitrary files.
Update the plugin.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 24, 2015
Multi Plugin Installer [multi-plugin-installer] < 1.2.0
unknown
The Multi Plugin Installer plugin for WordPress is vulnerable to Arbitrary File Read in versions before 1.2.0. This is due to vulnerable parameters 'filepath' and 'filename' in the mpi_download_file function. This makes it possible for unauthenticated attackers to read arbitrary files.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 24, 2015
Multi Plugin Installer [multi-plugin-installer] < 1.2.0 (closed)
unknown
The multi-plugin-installer WordPress plugin was affected by an Unauthenticated File Traversal security vulnerability.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database