mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
760 B
760 B
CVE-2015-7683
Description
Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.
POC
Reference
- http://packetstormsecurity.com/files/133930/WordPress-Font-7.5-Path-Traversal.html
- https://wpvulndb.com/vulnerabilities/8214