CyberRota Analysis
AI-GeneratedThe Yogeta WP Cloud plugin for WordPress versions up to 1.0 is vulnerable due to improper validation of user-supplied file paths, enabling unauthenticated attackers to exploit a public endpoint and download arbitrary files from the server. This flaw poses a significant risk as it can expose sensitive information, including credentials. WordPress site administrators using this plugin should prioritize immediate remediation to mitigate potential data breaches.
Original NVD Description
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.