WP Hide & Security Enhancer <= 1.3.9.2 - Arbitrary File Download
2017-07-21 00:00
Julio PotierStrategic Overview
StatusPatched in 1.4
Affected PluginWP Hide & Security Enhancer
Affected Version
<= 1.3.9.2CVSS7.5High
CVE
N/AVulnerability Overview
The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.4. This is due to insufficient validation on the file path supplied via the 'file_path' parameter. This makes it possible for attackers to arbitrarily download files such as the wp-config.php file.
Technical Analysis
REMEDIATION: Update to version 1.4, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C