Description
WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access sensitive files like wp-config.php outside the intended gallery directory.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
CrashBandicot
References
www.exploit-db.com/exploits/39589 (ExploitDB-39589)
fr.wordpress.org/plugins/hb-audio-gallery-lite/ (Official Product Homepage)
www.vulncheck.com/...llery-lite-path-traversal-file-download (VulnCheck Advisory: WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download)