The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-08-01T12:48:01

Updated: 2022-08-01T12:48:01

Reserved: 2022-05-04T00:00:00


Link: CVE-2022-1585

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-01T13:15:09.877

Modified: 2022-08-04T18:47:39.843


Link: CVE-2022-1585

JSON object: View

cve-icon Redhat Information

No data.

CWE