HomeDefault status
unaffected
Any version before 2.8.15
affected
Description
The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 2.8.15
Credits
Dogus DEMIRKIRAN
WPScan
References
wpscan.com/...rability/61d750a5-8c2c-4c94-a1a9-6a254c2a0d03/