CVE-2024-9939 - Overview, Insights & Trends

CVE-2024-9939

Published Jan 8, 2025

Last updated 20 days ago

CVSS high 7.5
WordPress

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-9939 affects the WordPress File Upload plugin. Specifically, versions up to and including 4.24.13 are vulnerable. The vulnerability is a Path Traversal issue located in the `wfu_file_downloader.php` file. This flaw allows unauthenticated attackers to read files outside of the intended directory.

Description
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.
Source
security@wordfence.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security@wordfence.com
CWE-22

Social media

Hype score
Not currently trending

Configurations