Access violation vulnerability in lote27 *

The lote27 theme for WordPress has a security vulnerability that makes it possible for unauthenticated attackers to download any file from the server. The vulnerability is found in the ‘download.php’ file, and is caused by the presence of a ‘download’ parameter. This could potentially give attackers access to sensitive information.

Detected in:

lote27 fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.