vendor:
admin-word-count-column
by:
Hassan Khan Yusufzai - Splint3r7
8.8
CVSS
HIGH
Local File Read
22
CWE
Product Name: admin-word-count-column
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: PHP 5.3.2 or below
2022
WordPress Plugin admin-word-count-column 2.2 – Local File Read
An attacker can exploit a Local File Read vulnerability in WordPress Plugin admin-word-count-column version 2.2. The vulnerability exists due to the lack of proper validation of user-supplied input in the 'path' parameter of the 'download-csv.php' script. A remote attacker can send a specially crafted request to the vulnerable script and read arbitrary files from the server. The attacker can also inject a null byte to bypass the file extension check and read any file from the server.
Mitigation:
Update to the latest version of the WordPress Plugin admin-word-count-column.