vendor:
zm_ajax_login_register
by:
Panagiotis Vagenas
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: zm_ajax_login_register
Affected Version From: 1.0.9
Affected Version To: 1.0.9
Patch Exists: YES
Related CWE: CVE-2015-4153
CPE: a:zanematthew:zm_ajax_login_register
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress 4.2.2
2015
CVE-2015-4153 – WordPress zM Ajax Login & Register Plugin [Local File Inclusion]
Any authenticated or non-authenticated user can perform a local file inclusion attack by exploiting the wp_ajax_nopriv_load_template action. Plugin simply includes the file specified in 'template' POST parameter without any further validation.
Mitigation:
Update to version 1.1.0