Record summary

CVE-2015-5469 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWordPress MDC YouTube Downloader 2.1.0 - Local File InclusionCVSS 7.5

WordPress MDC YouTube Downloader 2.1.0 plugin is susceptible to local file inclusion. A remote attacker can read arbitrary files via a full pathname in the file parameter to includes/download.php.

Impact

The vulnerability can lead to unauthorized access to sensitive files, execution of arbitrary code, and potential compromise of the entire WordPress installation.

Remediation

Update to the latest version of WordPress MDC YouTube Downloader plugin or apply the patch provided by the vendor.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2015cvewplfimdc_youtube_downloader_projectwordpressvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:mdc_youtube_downloader_project:mdc_youtube_downloader:2.1.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4