CVE-2015-5469
WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion
Record summary
CVE-2015-5469 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWordPress MDC YouTube Downloader 2.1.0 - Local File InclusionCVSS 7.5
WordPress MDC YouTube Downloader 2.1.0 plugin is susceptible to local file inclusion. A remote attacker can read arbitrary files via a full pathname in the file parameter to includes/download.php.
Impact
The vulnerability can lead to unauthorized access to sensitive files, execution of arbitrary code, and potential compromise of the entire WordPress installation.
Remediation
Update to the latest version of WordPress MDC YouTube Downloader plugin or apply the patch provided by the vendor.
Source: ProjectDiscovery