Publitio WordPress Plugin Path Traversal Vulnerability Allowing Arbitrary File Download
Vulnerability
A path traversal vulnerability has been identified in the Publitio WordPress plugin, allowing arbitrary file downloads. This issue affects versions through 2.2.0. The vulnerability arises from improper restrictions on pathname navigation, enabling unauthorized access to files on the server.
Impact
Exploitation of this vulnerability could lead to unauthorized downloading of files from the affected website, including sensitive information such as login credentials or backup files.
Remediation
Patchstack has issued a virtual patch to mitigate this vulnerability by blocking attacks until an official fix is available. Users can activate this virtual patch through the Patchstack service.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
