IP Blacklist Cloud < 3.43 - Directory Traversal
2015-03-13 00:00
James HookerStrategic Overview
Vulnerability Overview
The IP Blacklist Cloud plugin for WordPress is vulnerable to Directory Traversal in versions before 3.43 via the importCSVIPCloud function. This allows authenticated attackers with high-level privileges to read the contents of arbitrary files on the server, which can contain sensitive information.
Technical Analysis
REMEDIATION: Update to version 3.43, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C