PT-2024-37723 · WordPress · Ebook Store

Matthew Rollings

+1

·

Published

2024-08-02

·

Updated

2025-03-01

·

CVE-2024-6567

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ebook Store plugin for WordPress versions up to, and including, 5.8001
Description The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display errors set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own and requires another vulnerability to be present for damage to an affected website.
Recommendations For Ebook Store plugin for WordPress versions up to, and including, 5.8001: Update the plugin to a patched version immediately and monitor for signs of compromise. As a temporary workaround, consider restricting access to test files that have display errors set to true until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6567

Affected Products

Ebook Store