PT-2025-9827 · WordPress · Designthemes Core Features

Tonn

·

Published

2025-03-05

·

Updated

2025-03-06

·

CVE-2024-13471

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DesignThemes Core Features plugin for WordPress versions prior to 4.7
Description The issue allows unauthorized access to data due to a missing capability check on the dt process imported file function. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.
Recommendations For versions prior to 4.7, update to version 4.7 or later to resolve the issue. As a temporary workaround, consider disabling the dt process imported file function until a patch is available.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13471

Affected Products

Designthemes Core Features