CVE-2024-30492
WordPress Export and Import Users and Customers plugin <= 2.5.2 - Path Traversal vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.
LimitaciĆ³n inadecuada de un nombre de ruta a una vulnerabilidad de Restricted Directory ("Path Traversal") en WebToffee Import Export WordPress Users. Este problema afecta a los usuarios de Import Export WordPress: desde n/a hasta 2.5.2.
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-27 CVE Reserved
- 2024-03-28 CVE Published
- 2024-04-21 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Users Customers Import Export For Wp Woocommerce Search vendor "Users Customers Import Export For Wp Woocommerce" | Users Customers Import Export For Wp Woocommerce Search vendor "Users Customers Import Export For Wp Woocommerce" for product "Users Customers Import Export For Wp Woocommerce" | >= 0.0.0 <= 2.5.2 Search vendor "Users Customers Import Export For Wp Woocommerce" for product "Users Customers Import Export For Wp Woocommerce" and version " >= 0.0.0 <= 2.5.2" | en |
Affected
|