Impact
The CVE describes an arbitrary file download flaw in the WordPress CTX Feed plugin versions 6.6.47 and earlier. An attacker can send a crafted request to the plugin’s download endpoint, causing the plugin to serve any file located on the web server. This flaw corresponds to CWE‑22. The result is that sensitive files such as configuration data, WordPress core files, or source code can be exposed, leading to data loss and possibly providing material for further attacks.
Affected Systems
The vulnerability affects the WebAppick CTX Feed plugin for WordPress. All installations of the plugin with a version number of 6.6.47 or earlier are vulnerable. The issue is resolved in version 6.6.48 and later.
Risk and Exploitability
The CVSS score of 4.9 classifies the flaw as moderate. EPSS was not provided and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a crafted request to the plugin’s unauthorized download endpoint, which may be reachable without authentication. No elevated privileges are required for exploitation, but the attacker can potentially read any file on the server, increasing the risk of data leakage.
OpenCVE Enrichment