CVE-2024-9939

Published Jan 8, 2025

Last updated a month ago

CVSS high 7.5
WordPress

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-9939 affects the WordPress File Upload plugin. Specifically, versions up to and including 4.24.13 are vulnerable. The vulnerability is a Path Traversal issue located in the `wfu_file_downloader.php` file. This flaw allows unauthenticated attackers to read files outside of the intended directory.

Description
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.
Source
security@wordfence.com
NVD status
Modified
Products
wordpress_file_upload

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security@wordfence.com
CWE-22

Social media

Hype score
Not currently trending

Configurations