Beta

Report

MP3 Sticky Player <= 8.0 is vulnerable to Unauthenticated Arbitrary File Read/Download vulnerability

Unauthenticated
Published
2024-11-24

The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version.

CVSS

Score:7.5

Severity:High

Version: 8.0

There is a patch available in v8.1 and we strongly recommend you update to this version as soon as possible.