VulnerabilityModified
CVE-2015-7683
Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.
MEDIUM 4.0EPSS 5.00%
Does this matter?
Lower severity and a low EPSS score (5.00%). Track it; it rarely justifies an emergency change on its own.
Description
Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 5.00% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- font project/font
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/133930/WordPress-Font-7.5-Path-Traversal.htmlExploit
- http://www.securityfocus.com/archive/1/536670/100/0/threaded
- https://wordpress.org/plugins/font/changelog/Patch
- https://wpvulndb.com/vulnerabilities/8214
- http://packetstormsecurity.com/files/133930/WordPress-Font-7.5-Path-Traversal.htmlExploit
- http://www.securityfocus.com/archive/1/536670/100/0/threaded
- https://wordpress.org/plugins/font/changelog/Patch
- https://wpvulndb.com/vulnerabilities/8214
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.