Authentic <= 2.0.4 - Arbitrary File Download
highThe Authentic theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.0.4. This is due to insufficient input sanitization of the 'file' parameter. This makes it possible for unauthenticated attackers to download arbitrary files on the server, which can contain sensitive informat...
- CVSS:
- 7.5
- Affected:
- up to 2.0.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 7, 2014