ZeroHour

CVE-2023-7062

CVSS 3.1
8.8 high
EPSS
<1%p52
Published
()
Modified
Description

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

Ecosystems
WordPress
Weakness
CWE-538
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.