WORDFENCE-0afcdec7-dd22-4f10-b8f9-96a1e57d8f0b
high
📛 Threat Title
Thinkun Remind <= 1.1.3 - Directory Traversal
Description
The Thinkun Remind plugin for WordPress is vulnerable to arbitrary file reading via directory traversal in versions up to, and including, 1.1.3 via the 'exportData.php' file. This can allow unauthenticated attackers to extract sensitive data in system files that may be useful for performing subsequent attacks. Affected software — plugin: Thinkun Remind (affected: *-1.1.3). CVSS 7.5 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Thinkun RemindWordfence
Update to version 1.1.4, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.