WatchTowerHQ <= 3.6.15 - Unauthenticated Arbitrary File Download

2022-11-01 00:00
Dave Jong

Strategic Overview

Status
Patched in 3.6.16
Affected PluginWatchTowerHQ
Affected Version<= 3.6.15
CVSS8.6High
CVECVE-2022-44583
View all WatchTowerHQ vulnerabilities

Vulnerability Overview

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 3.6.15 due to missing capability checks on several REST API endpoints. This makes it possible for unauthenticated attackers to download arbitrary files on the affected site's server leading to Information Exposure.

Technical Analysis

REMEDIATION: Update to version 3.6.16, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C