1003 Mortgage Application
cpe:2.3:a:lenderd:1003_mortgage_application:*:*:*:*:wordpress:*:*
- <= 1.87
A full path disclosure vulnerability has been identified in the 1003 Mortgage Application plugin for WordPress, affecting all versions through 1.87. The issue arises because the file '/inc/class/fnm/export.php' is publicly accessible with error logging enabled. This configuration allows unauthenticated attackers to retrieve the full path of the web application, potentially aiding in the exploitation of other vulnerabilities. However, the disclosed information is not harmful on its own and requires the presence of another vulnerability to cause damage to the affected website.
Exploitation of this vulnerability could lead to unauthorized disclosure of the full server path, which may assist in further attacks against the website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.