vendor:
by:
6Scan security team
N/A
CVSS
N/A
Arbitrary file download and XSS
CWE
Product Name:
Affected Version From: < 3.1.1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2011
Count-per-day WordPress plugin Arbitrary file download and XSS
User could call a remote script to download arbitrary file from the target system. Another script was vulnerable to non-persistent XSS
Mitigation:
Official fix: This advisory is released after the vendor has responded and fixed the issue.