Vulnerabilities and security researches forrsfirewall rsfirewall
Direction: descendingJul 13, 2025
RSFirewall! # CVE-2025-7518
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 12, 2025
- Research Description
- The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 06, 2024
RSFirewall! # CVE-2021-4226
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 16, 2022
- Research Description
- RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable