PT-2024-17720 · WordPress · Wordpress File Upload

Lucio Sá

·

Published

2024-12-28

·

Updated

2025-01-07

·

CVE-2024-12719

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress File Upload plugin versions up to, and including, 4.24.15
Description The WordPress File Upload plugin is vulnerable to unauthorized access of data due to a missing capability check on the wfu ajax action read subfolders function. This allows authenticated attackers, with Subscriber-level access and above, to perform limited path traversal to view directories and subdirectories in WordPress. However, files cannot be viewed.
Recommendations For WordPress File Upload plugin versions up to, and including, 4.24.15, update to a version higher than 4.24.15 to resolve the issue. As a temporary workaround, consider restricting access to the wfu ajax action read subfolders function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-12719

Affected Products

Wordpress File Upload