ZeroHour

CVE-2024-13618

PoC
CVSS 3.1
7.2 high
EPSS
<1%p24
Published
()
Modified
Description

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Vendors
osteopathic
Products
downloadable by american osteopathic association
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.