wp-Table <= 1.43 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.43
- Fixed in:
- 1.44
- Disclosed:
- Aug 1, 2014
CVE-2007-2484 on NVD →
WP-Table [wp-table] < 1.44 (closed)
unknown
[en] PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.
- Affected:
- up to 1.44
- Fixed in:
- 1.44
- Disclosed:
- May 3, 2007
CVE-2007-2484 on NVD →
WP-Table [wp-table] < 1.44
unknown
[en] Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.
- Affected:
- up to 1.44
- Fixed in:
- 1.44
- Disclosed:
- May 3, 2007
CVE-2007-2483 on NVD →
WP-Table <= 1.43 - Local File Inclusion
critical
Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.43
- Fixed in:
- 1.44
- Disclosed:
- May 1, 2007
CVE-2007-2483 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database