PT-2025-2242 · WordPress · Music Sheet Viewer

Peter Thaleikis

·

Published

2025-01-30

·

Updated

2025-01-30

·

CVE-2024-13671

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Music Sheet Viewer plugin for WordPress versions up to and including 4.1
Description The issue allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information, through the read score file() function.
Recommendations For versions up to and including 4.1, consider disabling the read score file() function until a patch is available to prevent exploitation. Restrict access to sensitive files on the server to minimize the risk of information disclosure.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-13671

Affected Products

Music Sheet Viewer