PT-2024-16481 · WordPress · System Dashboard

Dogus Demirkiran

·

Published

2024-12-10

·

Updated

2025-10-09

·

CVE-2024-10708

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions System Dashboard WordPress plugin versions prior to 2.8.15
Description The issue is related to the plugin not validating user input used in a path, which could allow high privilege users, such as admin, to perform path traversal attacks and read arbitrary files on the server.
Recommendations For versions prior to 2.8.15, update to version 2.8.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for high privilege users until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-10708

Affected Products

System Dashboard