WORDFENCE-2240b2d3-b4cc-445f-b207-0ccbd527a0f3
high
📛 Threat Title
RokStories <= 1.25 - Full Path Disclosure
Description
The RokStories plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.25 via the 'src' parameter in the 'thumb.php' and 'rokstories.php' files. This can allow unauthenticated attackers to extract otherwise restricted system file paths. Affected software — plugin: RokStories (affected: *-1.25). CVSS 7.5 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: RokStoriesWordfence
Update to version 1.26, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.