MultiSafepay plugin for WooCommerce <= 4.15.0 - Arbitrary File Read
highThe MultiSafepay plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file read in versions up to, and including, 4.15.0 via the log_filename parameter. This is due to insufficient file path validation. This makes it possible for unauthenticated attackers to read arbitrary files on the server, includi...
- CVSS:
- 7.5
- Affected:
- up to 4.15.0
- Fixed in:
- 4.16.0
- Disclosed:
- Jul 18, 2022