Directory Traversal Vulnerability in Cart66 Lite Plugin for WordPress
CVE-2014-9461
Currently unrated
Summary
The Cart66 Lite plugin for WordPress contains a directory traversal vulnerability in the models/Cart66.php file. This flaw allows remote authenticated users to exploit the member_download action in wp-admin/admin-ajax.php, enabling them to read arbitrary files on the server. This could lead to the disclosure of sensitive information stored on the filesystem, posing a significant risk to the security of the affected system.
References
Timeline
Vulnerability Reserved
Vulnerability published