Posted by dxw Security on Oct 13
Details
================
Software: JM Twitter Cards
Version: 6.0
Homepage: https://wordpress.org/plugins/jm-twitter-cards
Advisory report:
https://security.dxw.com/advisories/full-path-disclosure-vulnerability-in-jm-twitter-cards-reveals-the-location-of-the-wordpress-installation-on-the-server/
CVE: Awaiting assignment
CVSS: 5 (Medium; AV:N/AC:L/Au:N/C:P/I:N/A:N)
Description
================
Full Path Disclosure vulnerability in JM Twitter…