PT-2024-16562 · WordPress · Mp3 Sticky Player

Tonn

·

Published

2024-11-23

·

Updated

2024-11-23

·

CVE-2024-10803

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MP3 Sticky Player plugin for WordPress versions up to, and including, 8.0
Description The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Recommendations For versions up to, and including, 8.0, update to the patched version released by the vendor, which is the same version as the affected version. As a temporary workaround, consider restricting access to the content/downloader.php file until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-10803

Affected Products

Mp3 Sticky Player