PT-2025-19720 · WordPress · Envolve Plugin

István Márton

·

Published

2025-05-05

·

Updated

2025-05-05

·

CVE-2024-11615

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Envolve Plugin versions up to, and including, 1.0
Description The Envolve Plugin for WordPress is vulnerable to arbitrary file deletion due to improper validation of a file or its path prior to deletion. This issue affects the zetra deleteLanguageFile and zetra deleteFontsFile functions, allowing unauthenticated attackers to delete language files.
Recommendations For Envolve Plugin version 1.0 and earlier, consider disabling the zetra deleteLanguageFile and zetra deleteFontsFile functions until a patch is available to prevent arbitrary file deletion. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-11615

Affected Products

Envolve Plugin