Posts in Page <= 1.2.4 - Authenticated Directory Traversal leading to Local File Inclusion
highThe Posts in Page plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.2.4 via the [ic_add_posts template] shortcode. This allows contributor-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 8.1
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Feb 13, 2017