Path Traversal Vulnerability Affects Landing Page Builder
CVE-2023-24379
6.8MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 May 2024
What is CVE-2023-24379?
A Path Traversal vulnerability was identified in the Web-Settler Landing Page Builder that allows attackers to exploit improper limitations on pathname restrictions. This vulnerability could enable unauthorized file access outside of intended directories, potentially compromising sensitive user data and compromising overall application integrity. Affected users running versions 3.1.9.9 and earlier should apply necessary patches and updates to secure their installations.
Affected Version(s)
Landing Page Builder – Free Landing Page Templates <= 3.1.9.9