Theme Editor < 2.6 - Authenticated Arbitrary File Download
CVE-2021-24154

4.9MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
5 April 2021

Summary

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

Affected Version(s)

Theme Editor 2.6

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Van Khanh - SunCSR (Sun* Cyber Security Research)
.