SEUR Oficial < 1.7.2 - Authenticated Arbitrary File Download
2022-01-10 00:00
José AguileraStrategic Overview
StatusPatched in 1.7.2
Affected PluginSEUR Oficial
Affected Version
< 1.7.2CVSS4.9Medium
CVE
CVE-2021-25004Vulnerability Overview
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.
Technical Analysis
REMEDIATION: Update to version 1.7.2, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C