Impact
The vulnerability is a Path Traversal flaw (CWE-22) that allows an attacker to specify a pathname outside the intended directory when requesting a file through the Easy Video Player Wordpress & WooCommerce plugin. This flaw can lead to downloading arbitrary files from the server that the web application has access to, including sensitive configuration files or code. The impact may compromise confidentiality and integrity of the site’s data, and could expose internal files that should remain private.
Affected Systems
The flaw affects the FWDesign Easy Video Player Wordpress & WooCommerce plugin for all versions up to and including 10.0. Users running any of these versions on a WordPress site are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates substantial risk, but the EPSS score of less than 1% suggests low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw remotely by crafting a request that exploits the path traversal, as the plugin does not properly restrict the requested file path. Once triggered, any file readable by the web server can be retrieved, potentially leading to data leakage or further compromise.
OpenCVE Enrichment
EUVD