HomeDefault status
unaffected
Any version before 2.2.2
affected
Description
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
Problem types
CWE-552 Files or Directories Accessible to External Parties
Product status
Any version before 2.2.2
Credits
Vuln Seeker Cybersecurity Team
WPScan
References
wpscan.com/...rability/c86157b0-43f3-4e82-9697-7dd9401b48d6/