ZeroHour

CVE-2016-10929

CVSS 3.0
5.3 medium
EPSS
1%p69
Published
()
Modified
Description

The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.

Vendors
advanced ajax page loader project
Products
advanced ajax page loader
Ecosystems
WordPress
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.