PT-2021-11015 · WordPress · Media File Organizer

Published

2021-07-07

·

Updated

2021-07-10

·

CVE-2020-24144

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Media File Organizer plugin version 1.0.1 for WordPress
Description: The issue allows an attacker to access files stored outside the web root folder via the items[] parameter in a move operation. This is a result of a directory traversal vulnerability in the Media File Organizer plugin for WordPress.
Recommendations: For Media File Organizer plugin version 1.0.1, consider disabling the move operation feature until a patch is available to prevent exploitation of the directory traversal vulnerability. Restrict access to sensitive files and folders to minimize the risk of unauthorized access.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24144

Affected Products

Media File Organizer