S4E just found a medium [ai] private ip disclosure detection scanner
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2011-1669 Scanner

CVE-2011-1669 scanner - Directory Traversal vulnerability in WP Custom Pages plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2011-1669
5.0
CVSS

Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The WP Custom Pages plugin for WordPress is a tool that allows users to create and manage custom pages for their website. It is widely used by businesses, bloggers, and website administrators who want to design unique and customized pages that stand out from the rest. With this plugin, users can easily add text, images, videos, links, and other interactive elements to their pages, without the need for any coding skills. The plugin is free to download and install, making it a popular choice among WordPress users.

However, the CVE-2011-1669 vulnerability detected in this product poses a significant risk to website owners. This vulnerability allows remote attackers to read arbitrary files via "..%2F" (encoded dot dot) sequences in the URL parameter. Attackers can exploit this vulnerability to gain unauthorized access to sensitive data stored on the server, such as user credentials, financial information, or confidential files. This vulnerability can also be used to execute arbitrary code on the system, which can result in a complete compromise of the website and server.

When exploited, this vulnerability can lead to a range of serious consequences for website owners. For instance, attackers can use the information they gather to launch targeted attacks against users or sell it on the dark web. They can also use the compromised website to distribute malware, spam, or phishing emails to unsuspecting victims. Furthermore, a successful attack can cause irreparable damage to a website's reputation, leading to loss of customer trust and business opportunities.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time threat intelligence, vulnerability scanning, and comprehensive reports that help users identify and mitigate security risks. By subscribing to this platform, website owners can ensure their digital assets are protected from various security threats, including the CVE-2011-1669 vulnerability detected in the WP Custom Pages plugin.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Update the WP Custom Pages plugin to the latest version, which has fixed the vulnerability
  • Implement a web application firewall (WAF) to block malicious requests and attacks
  • Use a strong and unique password for all user accounts and change them regularly
  • Restrict access to sensitive files and directories by using permissions and access control lists (ACLs)
  • Regularly scan the website for vulnerabilities and take immediate action to remediate them

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2011-1669 scanner - Directory Traversal vulnerability in WP Custom Pages plugin for WordPress S4E