5
CVSSv2

CVE-2014-2674

Published: 19/03/2018 Updated: 18/04/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote malicious users to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_navigation action to wp-admin/admin-ajax.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ajax-pagination project ajax-pagination 1.1

Exploits

Details ================ Software: Ajax Pagination (twitter Style) Version: 11 Homepage: wordpressorg/plugins/ajax-pagination/ CVSS: 93 (High; AV:N/AC:M/Au:N/C:C/I:C/A:C) Description ================ End-user exploitable local file inclusion vulnerability in Ajax Pagination (twitter Style) 11 Vulnerability ================ This plugin ...