Absolute path traversal vulnerability in Font.php in the Font plugin prior to 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
font project font |