CVE-2024-35162
EUVD-2024-3521722.05.2024, 06:15
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| wpfactory | download_plugins_and_themes_from_dashboard | 𝑥 < 1.8.6 | ADP |