SEUR Oficial < 1.7.2 - Authenticated Arbitrary File Download

2022-01-10 00:00
José Aguilera

Strategic Overview

Status
Patched in 1.7.2
Affected PluginSEUR Oficial
Affected Version< 1.7.2
CVSS4.9Medium
CVECVE-2021-25004
View all SEUR Oficial vulnerabilities

Vulnerability Overview

The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.

Technical Analysis

REMEDIATION: Update to version 1.7.2, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C