PT-2024-16699 · WordPress · Fileorganizer

Siunam

+1

·

Published

2024-12-07

·

Updated

2024-12-12

·

CVE-2024-11010

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FileOrganizer – Manage WordPress and Website Files plugin for WordPress versions up to, and including, 1.1.4
Description The issue allows authenticated attackers with Administrator-level access and above to include and execute arbitrary files on the server via the default lang parameter. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Recommendations For versions up to, and including, 1.1.4, update to a version higher than 1.1.4 to resolve the issue. As a temporary workaround, consider restricting access to the default lang parameter to minimize the risk of exploitation. Avoid using the default lang parameter in the affected plugin until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-11010

Affected Products

Fileorganizer