Unauthenticated Image Server Side Injection Vulnerability
CVE-2024-11219
7.5HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 27 November 2024
What is CVE-2024-11219?
The Otter Blocks plugin for WordPress is susceptible to a path traversal vulnerability in the get_image function, enabling unauthenticated attackers to access arbitrary images stored on the server. This could lead to the exposure of sensitive data. All versions up to and including 3.0.6 are affected, making it critical for users to apply the necessary updates and mitigate potential risks.
Affected Version(s)
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE * <= 3.0.6