SCv1 Theme (All Known Versions) - Arbitrary File Download
highThe SCv1 Theme for WordPress is vulnerable to Arbitrary File Download in all known versions. This is due to insufficient sanitization of user input on the 'file' parameter. This makes it possible for unauthenticated attackers to download arbitrary files, including configuration files.
- CVSS:
- 7.5
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Jun 10, 2014