Full Path Disclosure Vulnerability in 1003 Mortgage Application Plugin for WordPress
CVE-2024-13536
What is CVE-2024-13536?
The 1003 Mortgage Application plugin for WordPress is susceptible to Full Path Disclosure due to a publicly accessible error logging feature in the /inc/class/fnm/export.php file, affecting all versions up to and including 1.87. This vulnerability allows unauthenticated attackers to expose the application's full path, potentially serving as a stepping stone for further attacks. While the revealed information alone does not pose an immediate threat, it can facilitate subsequent exploitation if additional vulnerabilities are present.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
1003 Mortgage Application * <= 1.87
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved