What the vulnerability does
01Description
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
Explanation of Vulnerability in Simple Terms
WatchTowerHQ versions 3.6.15 and earlier contain an information disclosure vulnerability accessible over the network without authentication. An attacker can read sensitive data from the plugin without needing to log in or interact with a site administrator. This affects all installations running the vulnerable version.
What an attacker can do
Read sensitive information from the plugin without logging in.
Potential impact on your site
Sensitive data exposed to unauthenticated attackers; immediate update required to prevent data leakage.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources