Access violation vulnerability in GI-Media Library 3.0

The GI-Media Library plugin for WordPress, used in versions before 3.0, has a security vulnerability. An unauthenticated attacker, without needing to log in, can access the contents of any files on the server, including those with sensitive information. This is done through the ‘fileid’ parameter.

Detected in:

GI-Media Library open vulnerable versions: >= * < 3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.