The Project Source Code Download WordPress plugin up to and including 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
project-source-code-download project project-source-code-download 1.0.0 |