Directory Traversal Vulnerability in GD Rating System Plugin for WordPress
CVE-2018-5290
7.5HIGH
Summary
The GD Rating System plugin for WordPress is susceptible to a directory traversal vulnerability, which can be exploited through the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page. This vulnerability may allow an attacker to access sensitive files on the server, potentially leading to unauthorized data access and exploitation of the system. Users of this plugin should take immediate action to secure their installations against potential exploitation.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved