Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote malicious users to read arbitrary files via a full pathname in the file parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
swim team project swim team 1.44.10777 |