PT-2024-37723 · WordPress · Ebook Store
Matthew Rollings
+1
·
Published
2024-08-02
·
Updated
2025-03-01
·
CVE-2024-6567
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ebook Store plugin for WordPress versions up to, and including, 5.8001
Description
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display errors set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own and requires another vulnerability to be present for damage to an affected website.
Recommendations
For Ebook Store plugin for WordPress versions up to, and including, 5.8001: Update the plugin to a patched version immediately and monitor for signs of compromise.
As a temporary workaround, consider restricting access to test files that have display errors set to true until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ebook Store