Access violation vulnerability in Service Finder – Provider and Business Listing WordPress Theme 3.2

The Service Finder – Provider and Business Listing theme for WordPress is a vulnerable theme to a type of attack called ‘Path Traversal’. This type of attack can be used to gain access to sensitive information stored on the server. Versions of the theme up to version 3.2 were particularly vulnerable because of a ‘file’ parameter found in the downloads.php file, which allowed unauthenticated attackers to access the server and read the contents of any file.

Detected in:

Service Finder Bookings fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.