Simple Image Manipulator <= 1.0 - Remote File Download
mediumThe Simple Image Manipulator plugin for WordPress is vulnerable to Remote File Download in versions up to, and including, 1.0. This is due to no authorization checks or user input sanitization being performed in the './simple-image-manipulator/controller/download.php' file. This makes it possible for authenticated atta...
- CVSS:
- 6.5
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 2, 2015