Anti-Malware Security and Brute-Force Firewall
cpe:2.3:a:anti-malware_security_and_brute-force_firewall_project:anti-malware_security_and_brute-force_firewall:*:*:*:*:wordpress:*:*
- <= 4.23.81
This vulnerability is being actively exploited in the wild.
A vulnerability allowing arbitrary file read has been identified in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress, affecting all versions through 4.23.81. The issue arises from a missing capability check and information exposure in several AJAX actions, which enables authenticated attackers with Subscriber-level access and above to read arbitrary files on the server that may contain sensitive information.
Exploitation of this vulnerability allows authenticated users with Subscriber-level access and above to read sensitive files on the server.
Users are advised to update the plugin to version 4.23.83 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.