Secure Files [secure-files] < 1.2 (closed)
unknown
[en] A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function sf_downloads of the file secure-files.php. The manipulation of the argument downloadfile leads to path traversal. Upgrading to version 1.2 is able to address this is...
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Oct 29, 2023
CVE-2005-10002 on NVD →
secure-files <= 1.1 - Directory Traversal
medium
The secure-files plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1 via the downloadfile variable. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 1.1
- Fixed in:
- 1.2
- Disclosed:
- Oct 3, 2005
CVE-2005-10002 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database