Directory Traversal Vulnerability in Real3D Flipbook Lite Plugin for WordPress
CVE-2016-10966
7.5HIGH
Summary
The Real3D Flipbook Lite plugin version 1.0 for WordPress is susceptible to a directory traversal vulnerability that allows attackers to manipulate the 'bookName' parameter. By exploiting this flaw, unauthorized individuals may gain access to sensitive files on the server, which can lead to further compromises. Proper validation of user inputs is critical to mitigate such risks and ensure the security of the WordPress environment.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved