RedSteel (All Versions) - File Disclosure
highThe RedSteel theme for WordPress is vulnerable to Sensitive Data Exposure via the 'file' parameter in the 'download.php' file. This can allow unauthenticated attackers to extract sensitive data that can be used to perform future attacks.
- CVSS:
- 7.5
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Jan 26, 2015