vendor:
Firestats
by:
Jelmer de Hen
5.5
CVSS
MEDIUM
Remote Configuration File Download
200
CWE
Product Name: Firestats
Affected Version From: 1.6.2005
Affected Version To: 1.6.2005
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
WordPress firestats remote configuration file download
A vulnerability in the Firestats plugin for Wordpress allows an attacker to download the configuration file, which contains sensitive information such as the database username and password.
Mitigation:
Update to the latest version of Firestats plugin and ensure proper access controls are in place for sensitive files.