Simple Download Button Shortcode <= 1.0 - Information Disclosure via Arbitrary File Downloads
highThe Simple Download Button Shortcode plugin for WordPress is vulnerable to Arbitrary File Downloads in version 1.0. This is due to the plugin not properly validating the path of the file to be downloaded. This makes it possible for unauthenticated attackers to download arbitrary files that may contain sensitive data.
- CVSS:
- 7.5
- Affected:
- 1.0 – 1.0
- Fixed in:
- 1.1
- Disclosed:
- Sep 17, 2012