PT-2021-15771 · WordPress · Patreon Wordpress Plugin

Benedict Singer

+5

·

Published

2021-04-12

·

Updated

2021-04-14

·

CVE-2021-24227

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Patreon WordPress plugin versions prior to 1.7.0
Description: A Local File Disclosure issue was identified in the Patreon WordPress plugin that could be exploited by anyone visiting the site, potentially leading to the leakage of important internal files such as wp-config.php, which contains database credentials and cryptographic keys used for nonces and cookies generation.
Recommendations: For versions prior to 1.7.0, update to version 1.7.0 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24227

Affected Products

Patreon Wordpress Plugin