Directory Traversal Vulnerability in Cart66 Lite Plugin for WordPress
CVE-2014-9461

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 January 2015

Summary

The Cart66 Lite plugin for WordPress contains a directory traversal vulnerability in the models/Cart66.php file. This flaw allows remote authenticated users to exploit the member_download action in wp-admin/admin-ajax.php, enabling them to read arbitrary files on the server. This could lead to the disclosure of sensitive information stored on the filesystem, posing a significant risk to the security of the affected system.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.