Description
WordPress Plugin WP-DBManager is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. An attacker can exploit this issue to download the 'wp-config.php' script. This may allow attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin WP-DBManager version 2.60 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.61 or latest
References
Related Vulnerabilities
OpenVPN AS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2061)
WordPress Plugin bbPress SQL Injection (2.5.14)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Arbitrary File Upload (1.3.3.2)
Apache HTTP Server Out-of-bounds Read Vulnerability (CVE-2017-7668)