What the vulnerability does
01Description
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
Explanation of Vulnerability in Simple Terms
WPIDE File Manager & Code Editor versions 2.6 and earlier contain an information disclosure vulnerability. An authenticated administrator can read sensitive files on the server, including configuration files and other data not intended for web access. The vulnerability requires high-level admin privileges and does not allow file modification or deletion.
What an attacker can do
Read sensitive server files like wp-config.php and other configuration data.
Potential impact on your site
An admin account compromise exposes database credentials and other secrets stored in config files.
Conditions required to exploit
Attacker must have WordPress administrator account access.
Key dates
External resources