WORDFENCE-a2363a40-b627-44da-af8e-98821685c3ea
medium
📛 Threat Title
Eshop Magic < 0.2 - Arbitrary File Read
Description
The Eshop Magic plugin for WordPress is vulnerable to Arbitrary File Disclosure in versions before 0.2 via the 'file' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Affected software — plugin: Eshop Magic (affected: [*, 0.2)). CVSS 5.3 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Eshop MagicWordfence
Update to version 0.2, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.