CVE-2024-10585 Information
Jan 09, 2025
cve
Description
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to and including 1.13.0 via the ‘historyID’ parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://plugins.svn.wordpress.org/iwp-client/tags/1.13.0/debug-chart/index.php https://plugins.trac.wordpress.org/changeset/3202851/iwp-client/trunk/debug-chart/index.php https://www.wordfence.com/threat-intel/vulnerabilities/id/4d2518f6-3647-4bee-a98c-ce7f30375a62?source=cve
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: