PT-2016-3624 · WordPress · Wordpress Rename Plugin

Larry W. Cashdollar

+1

·

Published

2016-01-12

·

Updated

2016-06-27

·

CVE-2015-4703

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress Rename plugin version 1.0
Description The issue allows remote attackers to read arbitrary files via a full pathname in the dumpfname parameter in the mysqldump download.php file.
Recommendations For WordPress Rename plugin version 1.0, consider restricting access to the mysqldump download.php file until a patch is available. Avoid using the dumpfname parameter in the affected file to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4703

Affected Products

Wordpress Rename Plugin