PT-2024-24417 · Automattic · Wordpress

Apple502J

+4

·

Published

2024-06-25

·

Updated

2026-03-06

·

CVE-2024-32111

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WordPress versions 4.1 through 4.1.40 WordPress versions 4.2 through 4.2.37 WordPress versions 4.3 through 4.3.33 WordPress versions 4.4 through 4.4.32 WordPress versions 4.5 through 4.5.31 WordPress versions 4.6 through 4.6.28 WordPress versions 4.7 through 4.7.28 WordPress versions 4.8 through 4.8.24 WordPress versions 4.9 through 4.9.25 WordPress versions 5.0 through 5.0.21 WordPress versions 5.1 through 5.1.18 WordPress versions 5.2 through 5.2.20 WordPress versions 5.3 through 5.3.17 WordPress versions 5.4 through 5.4.15 WordPress versions 5.5 through 5.5.14 WordPress versions 5.6 through 5.6.13 WordPress versions 5.7 through 5.7.11 WordPress versions 5.8 through 5.8.9 WordPress versions 5.9 through 5.9.9 WordPress versions 6.0 through 6.0.8 WordPress versions 6.1 through 6.1.6 WordPress versions 6.2 through 6.2.5 WordPress versions 6.3 through 6.3.4 WordPress versions 6.4 through 6.4.4 WordPress versions 6.5 through 6.5.4
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a Path Traversal vulnerability. This allows Relative Path Traversal in Automattic WordPress.
Recommendations For WordPress versions 4.1 through 4.1.40, update to a version outside of this range. For WordPress versions 4.2 through 4.2.37, update to a version outside of this range. For WordPress versions 4.3 through 4.3.33, update to a version outside of this range. For WordPress versions 4.4 through 4.4.32, update to a version outside of this range. For WordPress versions 4.5 through 4.5.31, update to a version outside of this range. For WordPress versions 4.6 through 4.6.28, update to a version outside of this range. For WordPress versions 4.7 through 4.7.28, update to a version outside of this range. For WordPress versions 4.8 through 4.8.24, update to a version outside of this range. For WordPress versions 4.9 through 4.9.25, update to a version outside of this range. For WordPress versions 5.0 through 5.0.21, update to a version outside of this range. For WordPress versions 5.1 through 5.1.18, update to a version outside of this range. For WordPress versions 5.2 through 5.2.20, update to a version outside of this range. For WordPress versions 5.3 through 5.3.17, update to a version outside of this range. For WordPress versions 5.4 through 5.4.15, update to a version outside of this range. For WordPress versions 5.5 through 5.5.14, update to a version outside of this range. For WordPress versions 5.6 through 5.6.13, update to a version outside of this range. For WordPress versions 5.7 through 5.7.11, update to a version outside of this range. For WordPress versions 5.8 through 5.8.9, update to a version outside of this range. For WordPress versions 5.9 through 5.9.9, update to a version outside of this range. For WordPress versions 6.0 through 6.0.8, update to a version outside of this range. For WordPress versions 6.1 through 6.1.6, update to a version outside of this range. For WordPress versions 6.2 through 6.2.5, update to a version outside of this range. For WordPress versions 6.3 through 6.3.4, update to a version outside of this range. For WordPress versions 6.4 through 6.4.4, update to a version outside of this range. For WordPress versions 6.5 through 6.5.4, update to a version outside of this range.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2024-32111
BIT-WORDPRESS-MULTISITE-2024-32111
CVE-2024-32111

Affected Products

Wordpress