plugin

Simple Download Button Shortcode Vulnerabilities

1 known security issue reported for the Simple Download Button Shortcode WordPress plugin. Most recent disclosed Sep 17, 2012.

1 high

Running Simple Download Button Shortcode on your site? Check whether your installed version is affected.

Scan your site free

Simple Download Button Shortcode <= 1.0 - Information Disclosure via Arbitrary File Downloads

high

The Simple Download Button Shortcode plugin for WordPress is vulnerable to Arbitrary File Downloads in version 1.0. This is due to the plugin not properly validating the path of the file to be downloaded. This makes it possible for unauthenticated attackers to download arbitrary files that may contain sensitive data.

CVSS:
7.5
Affected:
1.0 – 1.0
Fixed in:
1.1
Disclosed:
Sep 17, 2012

CVE-2012-10016 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database