WP-Mon <= 0.5.1 - Arbitrary File Download
highThe WP-Mon plugin for WordPress is vulnerable to Arbitrary File Download via the 'download.php' file in versions up to, and including, 0.5.1. This makes it possible for unauthenticated attackers to download files including sensitive information that can be potentially used for future attacks.
- CVSS:
- 7.5
- Affected:
- up to 0.5.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 16, 2015