Impact
The vulnerability is a classic path traversal flaw that allows an attacker to retrieve any file on the server by supplying a specially crafted path to the Sports Rankings and Lists plugin. This flaw can expose sensitive configuration files, database backups or any other file accessible through the webroot, leading to potential compromise of confidentiality and further attacks.
Affected Systems
The issue affects the WordPress plugin Sports Rankings and Lists from vendors kutu62, versions up to and including 1.0.2. No higher versions are mentioned as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and no immediate public exploit is known. Successful exploitation would likely be performed over the public network, with a crafted HTTP request to a download endpoint that the plugin exposes, inferred as the likely attack vector; this may not require authentication.
OpenCVE Enrichment
EUVD