WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.7epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Apptha · Mac Photo Gallerypublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/41566unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.