Epic Church [epic-church] <= 3.6 (unfixed + closed)
unknown
[en] The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
- Affected:
- up to 3.6
- Fix:
- No patched version reported
- Disclosed:
- Sep 20, 2019
CVE-2014-10396 on NVD →
Epic Church by Organized Themes <= 3.6 - Arbitrary File Download
critical
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
- CVSS:
- 9.8
- Affected:
- up to 3.6
- Fix:
- No patched version reported
- Disclosed:
- Sep 8, 2014
CVE-2014-10396 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database