Xplodedthemes

Wpide

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Published 15.10.2024 00:15:21
  • Last modified 17.10.2024 13:34:27

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution ...

  • EPSS 1.12%
  • Published 21.09.2022 20:15:11
  • Last modified 20.02.2025 20:15:40

Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.

Exploit
  • EPSS 0.79%
  • Published 29.08.2022 18:15:09
  • Last modified 21.11.2024 07:00:38

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.