Local File Inclusion Vulnerability in Mail-Masta Plugin for WordPress
CVE-2016-10956
Key Information:
- Vendor
- Wordpress
- Status
- Vendor
- CVE Published:
- 16 September 2019
Badges
Summary
The Mail-Masta plugin version 1.0 for WordPress is susceptible to a local file inclusion vulnerability in the 'count_of_send.php' and 'csvexport.php' files. This flaw could allow an attacker to include local files on the server, potentially exposing sensitive information or enabling further exploitation of the web application. It is crucial for users of this plugin to apply security practices and consider updates to mitigate any risks associated with this vulnerability.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved