CVE-2024-35162: Wpfactory Download Plugins And Themes From Dashboard
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
Affected products
- Wpfactory Download Plugins And Themes From Dashboard: before 1.8.6 (fixed in 1.8.6)
- Wpfactory Llc Download Plugins And Themes From Dashboard: before 1.8.6 (fixed in 1.8.6)
Published 2024-05-22. Last modified 2026-06-17.