Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2539

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:file_away_project:file_away:*:*:*:*:*:wordpress:*:*
Версия до 3.9.9.0.1 (включая)

EPSS

Процентиль: 95%
0.20811
Средний

7.5 High

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
github
11 месяцев назад

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

EPSS

Процентиль: 95%
0.20811
Средний

7.5 High

CVSS3

Дефекты

CWE-327