Security Advisory

CVE-2024-13617

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-25 06:00:13
Last updated 2025-03-25 14:18:36
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server