Directory Traversal Vulnerability in GD Rating System Plugin for WordPress
CVE-2018-5287
7.5HIGH
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 8 January 2018
What is CVE-2018-5287?
The GD Rating System plugin for WordPress version 2.3 contains a directory traversal vulnerability within the wp-admin/admin.php panel. This flaw may permit unauthorized access to sensitive files on the server, posing a risk to the integrity and confidentiality of the application. Attackers can exploit this issue through crafted parameters, potentially leading to exposure of critical system files.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved