vendor:
CP Image Store with Slideshow
by:
Joaquin Ramirez Martinez
8.8
CVSS
HIGH
Arbitrary file download vulnerability
434
CWE
Product Name: CP Image Store with Slideshow
Affected Version From: 1.0.5
Affected Version To: 1.0.5
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:cp_image_store_with_slideshow:1.0.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 + Firefox
2015
WordPress CP Image Store with Slideshow 1.0.5 [Arbitrary file download vulnerability]
A vulnerability has been detected in the WordPress CP Image Store with Slideshow plugin in version 1.0.5. The vulnerability allows remote attackers to download arbitrary files from the server. The Arbitrary file download vulnerability is located in the `cp-image-store.php` file. The web vulnerability can be exploited by remote attackers without privileged application user account and without required user interaction. Successful exploitation of the Arbitrary file download vulnerability results in application compromise.
Mitigation:
Update to the latest version of the plugin, or disable the plugin if it is not needed.