Path Traversal Vulnerability in ABC Notation Plugin for WordPress
CVE-2024-13550
6.5MEDIUM
Summary
The ABC Notation plugin for WordPress is susceptible to a Path Traversal vulnerability due to improper handling of the 'file' attribute in the 'abcjs' shortcode. This issue allows authenticated attackers with Contributor-level access or higher to access and read arbitrary files on the server, potentially exposing sensitive information stored on the system. All versions of the plugin up to and including 6.1.3 are affected, making it critical for users to update to the latest version to mitigate this risk.
Affected Version(s)
ABC Notation * <= 6.1.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
muhammad yudha