CVE-2018-8719
WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclosure
Record summary
CVE-2018-8719 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information DisclosureExploitDB exploitby Colette ChamberlandNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress WP Security Audit Log 3.1.1 - Information DisclosureCVSS 5.3
WordPress WP Security Audit Log 3.1.1 plugin is susceptible to information disclosure. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the WordPress WP Security Audit Log plugin.
Remediation
Update to the latest version of WordPress WP Security Audit Log plugin (3.1.2 or higher) to fix the information disclosure vulnerability.
Source: ProjectDiscovery