MiwoFTP < 1.0.5 - Arbitrary File Download
2015-04-14 00:00
James HookerStrategic Overview
Vulnerability Overview
The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the improper use of a hook which utilizes a download file function. This makes it possible for unauthenticated attackers to arbitrarily download files located within the home directory of the affected site.
Technical Analysis
REMEDIATION: Update to version 1.0.5, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C