Fast Velocity Minify <= 2.7.6 - Full Path Disclosure
2019-10-16 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 2.7.7
Affected PluginFast Velocity Minify
Affected Version
<= 2.7.6CVSS4.3Medium
CVE
CVE-2019-19983Vulnerability Overview
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.
Technical Analysis
REMEDIATION: Update to version 2.7.7, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C