vendor:
Site Editor Wordpress Plugin
by:
author
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: Site Editor Wordpress Plugin
Affected Version From: 1.1.1
Affected Version To: 1.1.1
Patch Exists: YES
Related CWE: CVE-2018-7422
CPE: a:site_editor:site_editor_wordpress_plugin
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
Local File Inclusion vulnerability in Site Editor WordPress Plugin
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php.
Mitigation:
No fix available yet.