PT-2024-32537 · WordPress · Ex-Themes Wp Timeline
Bonds
·
Published
2024-10-05
·
Updated
2024-10-09
·
CVE-2024-47324
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin versions through 3.6.7
Description
The Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin has a Path Traversal vulnerability, also known as Improper Limitation of a Pathname to a Restricted Directory. This issue allows PHP Local File Inclusion, enabling users to include local files, potentially leading to security breaches.
Recommendations
For Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin versions through 3.6.7, update to a version later than 3.6.7 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ex-Themes Wp Timeline