Thinkun Remind <= 1.1.3 - Directory Traversal
high
The Thinkun Remind plugin for WordPress is vulnerable to arbitrary file reading via directory traversal in versions up to, and including, 1.1.3 via the 'exportData.php' file. This can allow unauthenticated attackers to extract sensitive data in system files that may be useful for performing subsequent attacks.
- CVSS:
- 7.5
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Jun 8, 2012
Thinkun Remind [thinkun-remind] < 1.1.4 (closed)
unknown
WordPress Tinymce Thumbnail plugin is prone to a remote file disclosure vulnerability. It allows an attacker to compromise encrypted login credentials for or retrieve the device's administrator password allowing them to directly access the device's configuration control panel.
Update the plugin.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Jun 8, 2012
Thinkun Remind [thinkun-remind] < 1.1.4 (closed)
unknown
The Thinkun Remind plugin for WordPress is vulnerable to arbitrary file reading via directory traversal in versions up to, and including, 1.1.3 via the 'exportData.php' file. This can allow unauthenticated attackers to extract sensitive data in system files that may be useful for performing subsequent attacks.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Jun 8, 2012
Thinkun Remind [thinkun-remind] <= 1.1.3 (unfixed + closed)
unknown
The thinkun-remind WordPress plugin was affected by an exportData.php dirPath Parameter Traversal Arbitrary File Access security vulnerability.
- Affected:
- up to 1.1.3
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database