PT-2024-16572 · WordPress · Luna Radio Player

Tonn

·

Published

2024-11-13

·

Updated

2024-11-13

·

CVE-2024-10816

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LUNA RADIO PLAYER plugin for WordPress versions up to, and including, 6.24.01.24
Description The issue allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information, via the js/fallback.php file. This is a Directory Traversal weakness.
Recommendations For versions up to, and including, 6.24.01.24, consider disabling access to the js/fallback.php file as a temporary workaround until a patch is available. Restrict access to sensitive files on the server to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-10816

Affected Products

Luna Radio Player