WP Hide & Security Enhancer <= 1.3.9.2 - Arbitrary File Download

2017-07-21 00:00
Julio Potier

Strategic Overview

Status
Patched in 1.4
Affected Version<= 1.3.9.2
CVSS7.5High
CVEN/A
View all WP Hide & Security Enhancer vulnerabilities

Vulnerability Overview

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.4. This is due to insufficient validation on the file path supplied via the 'file_path' parameter. This makes it possible for attackers to arbitrarily download files such as the wp-config.php file.

Technical Analysis

REMEDIATION: Update to version 1.4, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C