Social Discussions <= 6.1.1 - Remote File Inclusion and Full Path Disclosure
criticalThe Social Discussions plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 6.1.1 via the HTTP_ENV_VARS parameter. This allows unauthenticated attackers to include remote files on the server, resulting in code execution. The plugin is also vulnerable to Full Path Disclosure via...
- CVSS:
- 9.8
- Affected:
- up to 6.1.1
- Fixed in:
- 6.1.2
- Disclosed:
- Oct 17, 2012