vendor:
Membership Simplified for OAP Members Only
by:
Munir Njiru
9,8
CVSS
CRITICAL
Arbitrary File Download
23
CWE
Product Name: Membership Simplified for OAP Members Only
Affected Version From: 1.58
Affected Version To: 1.58
Patch Exists: YES
Related CWE: CVE-2017-1002008
CPE: a:wordpress:membership_simplified_for_oap_members_only:1.58
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
WordPress Plugin Membership Simplified v1.58 – Arbitrary File Download
This exploit allows an attacker to download arbitrary files from a vulnerable Wordpress Plugin Membership Simplified v1.58 installation. The attacker can specify the file to download by manipulating the download_file parameter in the download.php file.
Mitigation:
Upgrade to the latest version of the plugin or disable the plugin if it is not necessary.