WP PHP Widget <= 1.0.2 - Full Path Disclosure
mediumwp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
- CVSS:
- 5.3
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014