Swim Team < 1.45.1085 - Directory Traversal
mediumAbsolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.
- CVSS:
- 5.3
- Affected:
- up to 1.44.1077
- Fixed in:
- 1.45.1085
- Disclosed:
- Jul 8, 2015