CVE Published: 14/09/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: larry_cashdollar |
Vendor: William DeAngelis |
Product: membership-simplified-for-oap-members-only Status : PUBLISHED
CVE-2017-1002008 Description
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.