CVE-2024-11219 Information

Description

The Otter Blocks – Gutenberg Blocks Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to and including 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images on the server which can contain sensitive information.

Reference

https://plugins.trac.wordpress.org/browser/otter-blocks/tags/3.0.6/inc/plugins/class-dynamic-content.php#L222 https://www.wordfence.com/threat-intel/vulnerabilities/id/c5e9ab63-d61e-40f1-a5cb-432f33dfd2a6?source=cve

Share on: