Really Simple Guest Post <= 1.0.6 - Local File Inclusion
critical
The Really Simple Guest Post plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6 via the 'rootpath' parameter passed to the require_once function. This allows unauthorized attackers to include and execute arbitrary files on the server, allowing the execution of any PHP cod...
- CVSS:
- 9.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Jun 5, 2015
Really Simple Guest Post Plugin [really-simple-guest-post] < 1.0.7 (closed)
unknown
Because of this vulnerability, an attacker can come directly into the URL /wp-content/plugins/really-simple-guest-post/simple-guest-post-submit.php and send a post data.
Update the plugin.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Jun 5, 2015
Really Simple Guest Post Plugin [really-simple-guest-post] < 1.0.7 (closed)
unknown
The Really Simple Guest Post plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6 via the 'rootpath' parameter passed to the require_once function. This allows unauthorized attackers to include and execute arbitrary files on the server, allowing the execution of any PHP cod...
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Jun 5, 2015
Really Simple Guest Post Plugin [really-simple-guest-post] < 1.0.7 (closed)
unknown
The really-simple-guest-post WordPress plugin was affected by a File Include security vulnerability.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database