Record summary

CVE-2015-1000012 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWordPress MyPixs <=0.3 - Local File InclusionCVSS 7.5

WordPress MyPixs 0.3 and prior contains a local file inclusion vulnerability.

Impact

An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or gain unauthorized access to the server.

Remediation

Update to the latest version of the MyPixs plugin (>=0.4) or apply the vendor-provided patch to fix the LFI vulnerability.

WeaknessesCWE-200
Authorsdaffainfo
Template tagscvecve2015wordpresswp-pluginlfiwpscanmypixs_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:mypixs_project:mypixs:0.3:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/mypixs"

Source: ProjectDiscovery

References

3