CVE-2016-10929

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
22/08/2019
Last modified:
23/08/2019

Description

The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advanced_ajax_page_loader_project:advanced_ajax_page_loader:*:*:*:*:*:wordpress:*:* 2.7.7 (excluding)


References to Advisories, Solutions, and Tools