Tinymce Thumbnail Gallery <= 1.0.7 - Local File Inclusion
highThe Tinymce Thumbnail Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.7 via the 'href' parameter found in the ~/php/download-image.php file that can be directly accessed. This makes it possible for unauthenticated attackers to retrieve information from local file...
- CVSS:
- 7.5
- Affected:
- up to 1.0.7
- Fixed in:
- 1.1.0
- Disclosed:
- Aug 1, 2014