Vulnerabilities > CVE-2022-2357 - Files or Directories Accessible to External Parties vulnerability in WSM Downloader Project WSM Downloader 1.4.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
wsm-downloader-project
CWE-552

Summary

The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.

Vulnerable Configurations

Part Description Count
Application
Wsm_Downloader_Project
1