CVE-2015-9470: Ionadas History Collection

High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.

The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.

Affected products

  • Ionadas History Collection: up to and including 1.1.1

Published 2019-10-10. Last modified 2026-06-17.