Vulnerabilities > Themeeditor
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-05 | CVE-2021-24154 | Files or Directories Accessible to External Parties vulnerability in Themeeditor Theme Editor The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd | 4.9 |