Description
WordPress Plugin WP-DBManager is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. An attacker can exploit this issue to download the 'wp-config.php' script. This may allow attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin WP-DBManager version 2.60 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.61 or latest
References
Related Vulnerabilities
Jboss EAP Improper Input Validation Vulnerability (CVE-2016-3110)
Magento Improper Authentication Vulnerability (CVE-2019-8108)
Atlassian Jira Incorrect Behavior Order: Validate Before Canonicalize Vulnerability (CVE-2022-26137)
WordPress Plugin Lazyest Backup 'xml_or_all' Parameter Cross-Site Scripting (0.2.1)