PT-2025-6562 · WordPress · Actionwear Products Sync Plugin

Matthew Rollings

·

Published

2025-02-18

·

Updated

2025-02-24

·

CVE-2024-13535

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Actionwear products sync plugin for WordPress versions up to, and including, 2.3.0
Description The issue is due to the composer-setup.php file being publicly accessible with display errors set to true, allowing unauthenticated attackers to retrieve the full path of the web application. This information can be used to aid other attacks, but it is not useful on its own and requires another vulnerability to be present for damage to an affected website.
Recommendations For versions up to, and including, 2.3.0, consider updating to a version where the display errors setting is not publicly accessible or set to false to prevent the full path disclosure. As a temporary workaround, consider restricting access to the composer-setup.php file until a patch is available.

Fix

Generation of Error Message Containing Sensitive Information

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-13535

Affected Products

Actionwear Products Sync Plugin