CVE-2024-11605
Published Dec 27, 2024The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform…
Vendor/product archive
2 CVEs tagged to wp-publications_project / wp-publications — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform…
The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to inc…