PT-2025-6562 · WordPress · Actionwear Products Sync Plugin
Matthew Rollings
·
Published
2025-02-18
·
Updated
2025-02-24
·
CVE-2024-13535
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Actionwear products sync plugin for WordPress versions up to, and including, 2.3.0
Description
The issue is due to the composer-setup.php file being publicly accessible with
display errors set to true, allowing unauthenticated attackers to retrieve the full path of the web application. This information can be used to aid other attacks, but it is not useful on its own and requires another vulnerability to be present for damage to an affected website.Recommendations
For versions up to, and including, 2.3.0, consider updating to a version where the
display errors setting is not publicly accessible or set to false to prevent the full path disclosure. As a temporary workaround, consider restricting access to the composer-setup.php file until a patch is available.Fix
Generation of Error Message Containing Sensitive Information
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Actionwear Products Sync Plugin