RSFirewall! <= 1.1.42 - Authenticated (Admin+) Arbitrary File Read

CVE Details

Basic Information

Title RSFirewall! <= 1.1.42 - Authenticated (Admin+) Arbitrary File Read
Type cve
Published 2025-07-12T09:24:28.763Z
Modified 2025-07-12T09:24:28.763Z

Product Information

Vendor rsjoomla
Product RSFirewall!
Version *

CVSS Information

Base Score 4.9 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Analysis

AI Description The RSFirewall! WordPress plugin is vulnerable to Path Traversal, allowing authenticated administrators to read arbitrary files, potentially exposing sensitive information.
AI Severity Medium
AI Vendor WordPress Community
AI Product RSFirewall!
AI Version <= 1.1.42

Affected Products

  • rsjoomla RSFirewall! *

Additional Information

CWE List CWE-22
Source Wordfence

Description

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.