CVE-2025-2267
CVE-2025-2267
Título es
CVE-2025-2267
Sáb, 15/03/2025 – 04:15
Tipo
CWE-862
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-2267
Descripción en
The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information.
15/03/2025
15/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
6.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://plugins.trac.wordpress.org/browser/wp01/trunk/inc/class-wp01.php#L109
https://wordpress.org/plugins/wp01/
https://www.wordfence.com/threat-intel/vulnerabilities/id/900d09e8-ded5-49b9-81bf-ddfc85d3cf2b?source=cve
Enviar en el boletín
Off
