Vulnerabilities > Themeeditor

DATE CVE VULNERABILITY TITLE RISK
2021-04-05 CVE-2021-24154 Files or Directories Accessible to External Parties vulnerability in Themeeditor Theme Editor
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
network
low complexity
themeeditor CWE-552
4.9