Youtube Freedown <= 1.0 - Remote Media File Inclusion
criticalThe Youtube Freedown plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including, 1.0 via the player.swf file. This allows unauthenticated attackers to include remote files on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- May 25, 2014