Vulnerabilities
Vulnerable Software
The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server
CVSS Score
8.6
EPSS Score
0.001
Published
2025-03-25
The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
CVSS Score
7.2
EPSS Score
0.001
Published
2025-03-25


Contact Us

Shodan ® - All rights reserved