PT-2024-3157 · WordPress · Wp Automatic

Rafie Muhammad

·

Published

2024-02-25

·

Updated

2025-04-04

·

CVE-2024-27954

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Automatic versions through 3.92.0
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a 'Path Traversal' vulnerability, in WP Automatic. This vulnerability allows for Path Traversal and Server Side Request Forgery (SSRF) attacks. The vulnerability is associated with insufficient validation of incoming requests, which can be exploited by a remote attacker to conduct an SSRF attack.
Recommendations For versions through 3.92.0, update to a version later than 3.92.0 to resolve the issue. As a temporary workaround, consider restricting access to the downloader.php script to minimize the risk of exploitation. Avoid using the vulnerable WP Automatic plugin until the issue is resolved.

Exploit

Fix

Path traversal

SSRF

Weakness Enumeration

Related Identifiers

BDU:2024-03370
CVE-2024-27954

Affected Products

Wp Automatic