wptf-image-gallery <= 1.0.3 - Arbitrary File Download

2015-07-18 00:00
Larry W. Cashdollar

Strategic Overview

Status
Unpatched
Affected Pluginwptf-image-gallery
Affected Version<= 1.0.3
CVSS7.5High
CVECVE-2015-1000007
View all wptf-image-gallery vulnerabilities

Vulnerability Overview

The wptf-image-gallery plugin for WordPress is vulnerable to Arbitrary File Downloads in versions up to, and including, 1.0.3 via the './wptf-image-gallery/lib-mbox/ajax_load.php' file. This makes it possible for unauthenticated attackers to download sensitive files from the vulnerable system.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C