Path Traversal Vulnerability in ABC Notation Plugin for WordPress
CVE-2024-13550
6.5MEDIUM
What is CVE-2024-13550?
The ABC Notation plugin for WordPress is susceptible to a Path Traversal vulnerability due to improper handling of the 'file' attribute in the 'abcjs' shortcode. This issue allows authenticated attackers with Contributor-level access or higher to access and read arbitrary files on the server, potentially exposing sensitive information stored on the system. All versions of the plugin up to and including 6.1.3 are affected, making it critical for users to update to the latest version to mitigate this risk.
Affected Version(s)
ABC Notation * <= 6.1.3