WHMPress WordPress Plugin Path Traversal Vulnerability Allowing Local File Inclusion
Vulnerability
A path traversal vulnerability has been identified in the WHMPress WordPress plugin, specifically in versions through 6.2-revision-9. This vulnerability allows for relative path traversal, which could be exploited to include local files from the target website and display their contents. Such an exploitation could potentially lead to a complete takeover of the database, depending on the site's configuration.
Impact
Exploitation of this vulnerability could result in local file inclusion, allowing attackers to read sensitive files on the server. In some cases, this could lead to a database takeover, depending on the site's configuration.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
