Sell Downloads <= 1.0.7 - Improper Input Validation

2015-07-10 00:00
Anonymous

Strategic Overview

Status
Patched in 1.0.8
Affected PluginSell Downloads
Affected Version< 1.0.8
CVSS7.5High
CVECVE-2015-9348
View all Sell Downloads vulnerabilities

Vulnerability Overview

The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

Technical Analysis

REMEDIATION: Update to version 1.0.8, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C