CVE-2018-7422

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/03/2018
Last modified:
24/08/2020

Description

A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siteeditor:site_editor:*:*:*:*:*:wordpress:*:* 1.1.1 (including)