Path Traversal Vulnerability Affects Instant Chat Floating Button for WordPress Websites
CVE-2024-44018
7.5HIGH
Key Information
- Vendor
- Istmo Plugins
- Status
- Instant Chat Floating Button For WordPress Websites
- Vendor
- CVE Published:
- 5 October 2024
Summary
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Istmo Plugins Instant Chat Floating Button for WordPress Websites allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress Websites: from n/a through 1.0.5.
Affected Version(s)
Instant Chat Floating Button for WordPress Websites <= 1.0.5
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
tahu.datar (Patchstack Alliance)