← Back

Wsm Downloader Project

wsm_downloader_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wsm Downloader Project
1Wsm Downloader
Nov 21, 2024
Aug 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation
1Wsm Downloader Project
1Wsm Downloader
Nov 21, 2024
Aug 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.