Where I Was, Where I Will Be <= 1.1.1 - Unauthenticated Remote File Inclusion
criticalThe Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter of the /system/include/include_user.php file. This makes it possible for unauthenticated attackers to include and execute arbitrary files hosted on external servers, allowing the...
- CVSS:
- 9.8
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 13, 2024