WordPress WP Security Audit Log 3.1.1 plugin is susceptible to information disclosure. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2018-8719
info:
name: WordPress WP Security Audit Log 3.1.1 - Information Disclosure
au
...