Vulnerabilities
Codoforum 2.5.1 Arbitrary File Download
str_replace() is used to sanitize file path but function output is not assigned to variable.
10-03-2015
1 MIN READ
Vulnerabilities
str_replace() is used to sanitize file path but function output is not assigned to variable.
1 MIN READ
Vulnerabilities
Using basic_settings() we can update every WordPress options, for example
1 MIN READ
Vulnerabilities
$_REQUEST['title'] is not escaped.
1 MIN READ
Vulnerabilities
$_REQUEST['widget'] is not escaped.
1 MIN READ
Vulnerabilities
Package functions are accessible to every registered users because admin privileges are not checked properly.
1 MIN READ
Vulnerabilities
wp_ajax_save_item() is accessible for every registered user (admin privileges are not checked).
1 MIN READ
Vulnerabilities
There is few places where `Database
2 MIN READ
Vulnerabilities
Every registered user can access UploadHandler.php.
2 MIN READ