First published: Tue Jun 19 2012(Updated: )
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Newsletters plugin | =1.5 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3588 is considered a high severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2012-3588, upgrade the Plugin Newsletter to a version that is not affected by this vulnerability.
CVE-2012-3588 facilitates directory traversal attacks, allowing attackers to read arbitrary files on the server.
CVE-2012-3588 affects version 1.5 of the Plugin Newsletter for WordPress.
No, CVE-2012-3588 is specifically a vulnerability in the Plugin Newsletter plugin, not WordPress itself.