The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user
2022-08-22T15:15:15.483
2024-11-21T07:01:14.797
Modified
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | radiustheme | team_-_wordpress_team_members_showcase | < 4.1.2 | Yes |