plugin

Thinkun Remind Vulnerabilities

4 known security issues reported for the Thinkun Remind WordPress plugin. Most recent disclosed Jun 8, 2012.

1 high

Running Thinkun Remind on your site? Check whether your installed version is affected.

Scan your site free

Thinkun Remind <= 1.1.3 - Directory Traversal

high

The Thinkun Remind plugin for WordPress is vulnerable to arbitrary file reading via directory traversal in versions up to, and including, 1.1.3 via the 'exportData.php' file. This can allow unauthenticated attackers to extract sensitive data in system files that may be useful for performing subsequent attacks.

CVSS:
7.5
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jun 8, 2012

Thinkun Remind [thinkun-remind] < 1.1.4 (closed)

unknown

WordPress Tinymce Thumbnail plugin is prone to a remote file disclosure vulnerability. It allows an attacker to compromise encrypted login credentials for or retrieve the device's administrator password allowing them to directly access the device's configuration control panel. Update the plugin.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Jun 8, 2012

Thinkun Remind [thinkun-remind] < 1.1.4 (closed)

unknown

The Thinkun Remind plugin for WordPress is vulnerable to arbitrary file reading via directory traversal in versions up to, and including, 1.1.3 via the 'exportData.php' file. This can allow unauthenticated attackers to extract sensitive data in system files that may be useful for performing subsequent attacks.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Jun 8, 2012

Thinkun Remind [thinkun-remind] <= 1.1.3 (unfixed + closed)

unknown

The thinkun-remind WordPress plugin was affected by an exportData.php dirPath Parameter Traversal Arbitrary File Access security vulnerability.

Affected:
up to 1.1.3
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database