Executive brief
The AR for WordPress plugin is used to manage augmented reality content on WordPress websites. A security flaw in this plugin allows unauthorized individuals to access and read sensitive files stored on the website's server. This could lead to the exposure of configuration files, login credentials, or other private data, potentially compromising the entire website.
Technical details
A directory traversal vulnerability exists in the AR for WordPress plugin due to insufficient validation of the 'file' parameter in the ar-secure-download.php component. An unauthenticated attacker can exploit this by obtaining a valid nonce and secure nonce through the ar_get_fresh_nonce and ar_process_user_image AJAX handlers. On default or unlicensed installations where the license key is unset, the encryption key can be reproduced locally, allowing the attacker to craft requests that read arbitrary files from the server. This vulnerability is tracked as CWE-22 and affects all versions up to 8.40.
Affected products
- webandprint AR for WordPress Up to and including 8.40
Timeline
- 2026-07-03: disclosed: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/ar-wordpress.php
- https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/ar-wordpress.php
- https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/includes/ar-secure-download.php
- https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/includes/ar-secure-download.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3593272%40ar-for-wordpress&new=3593272%40ar-for-wordpress&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cfa375a8-ab07-45da-bc77-1e7edc996e05?source=cve