5
CVSSv2

CVE-2014-8801

Published: 28/11/2014 Updated: 23/03/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin prior to 1.7.15 for WordPress allows remote malicious users to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

strangerstudios paid memberships pro

Exploits

# Exploit Title: Paid Memberships Pro 17142 Path Traversal # Date: 14-10-2014 # Exploit Author: Kacper Szurek - securityszurekpl # Software Link: downloadswordpressorg/plugin/paid-memberships-pro17142zip # Category: webapps # CVE: CVE-2014-8801 1 Description getfilephp is accessible to everyone is_admin() is used t ...
Paid Memberships Pro version 17142 suffers from a path traversal vulnerability ...