PT-2025-9827 · WordPress · Designthemes Core Features

Tonn

·

Publicado

2025-03-05

·

Atualizado

2025-03-06

·

CVE-2024-13471

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DesignThemes Core Features plugin for WordPress versions prior to 4.7
Description The issue allows unauthorized access to data due to a missing capability check on the dt process imported file function. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.
Recommendations For versions prior to 4.7, update to version 4.7 or later to resolve the issue. As a temporary workaround, consider disabling the dt process imported file function until a patch is available.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-13471

Produtos afetados

Designthemes Core Features