Propovoice
cpe:2.3:a:propovoice:propovoice:*:*:*:*:wordpress:*:*
- <= 1.7.6.7
A vulnerability allowing arbitrary file read has been identified in the Propovoice: All-in-One Client Management System plugin for WordPress, affecting all versions through 1.7.6.7. The issue arises in the send_email() function, where unauthenticated attackers can read the contents of arbitrary files on the server, potentially exposing sensitive information.
Exploitation of this vulnerability allows for unauthorized access to arbitrary files on the server, which could contain sensitive information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.