WordPress Theme Editor plugin <= 2.5 - Multiple Authenticated Arbitrary File Download vulnerabilities
- Theme Editor
- Multiple Authenticated Arbitrary File Download vulnerabilities found by Nguyen Van Khanh and WPScan security research team in WordPress Theme Editor plugin (versions <= 2.5).
- Update the WordPress Theme Editor plugin to the latest available version (at least 2.6).
Type Arbitrary File Download
OWASP Top 10 A6: Sensitive Data Exposure
- Name CVE-N/A
Fixed In 2.6
- Disclosure date
- Nguyen Van Khanh