Unauthorized File Inclusion Vulnerability in Shariff Wrapper Plugin for WordPress
CVE-2024-4098

9.8CRITICAL

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 June 2024

Summary

The Shariff Wrapper plugin for WordPress is vulnerable to a Local File Inclusion (LFI) issue in versions up to and including 4.6.13 due to a flaw in the shariff3uu_fetch_sharecounts function. This vulnerability allows unauthenticated attackers to include and execute arbitrary files on the server. Exploiting this flaw could lead to the execution of any PHP code contained within those files, enabling attackers to bypass existing access controls, access sensitive data, or execute malicious scripts when 'safe' file types, such as images, are uploaded and included. It's crucial for users of the Shariff Wrapper plugin to upgrade to the latest secure version to mitigate these risks.

Affected Version(s)

Shariff Wrapper * <= 4.6.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

haidv35
.