IP Blacklist Cloud < 3.43 - Directory Traversal

2015-03-13 00:00
James Hooker

Strategic Overview

Status
Patched in 3.43
Affected PluginIP Blacklist Cloud
Affected Version< 3.43
CVSS4.9Medium
CVEN/A
View all IP Blacklist Cloud vulnerabilities

Vulnerability Overview

The IP Blacklist Cloud plugin for WordPress is vulnerable to Directory Traversal in versions before 3.43 via the importCSVIPCloud function. This allows authenticated attackers with high-level privileges to read the contents of arbitrary files on the server, which can contain sensitive information.

Technical Analysis

REMEDIATION: Update to version 3.43, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C