Path Traversal Vulnerability in WP Timeline Plugin Allows PHP Local File Inclusion
CVE-2024-47324
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 October 2024
What is CVE-2024-47324?
A vulnerability exists within the Ex-Themes WP Timeline β Vertical and Horizontal timeline plugin for WordPress that allows for improper limitations of a pathname, leading to potential local file inclusion exploits. This security flaw can be targeted by attackers to gain unauthorized access to sensitive files on the server, thereby compromising the integrity and confidentiality of the affected systems. Versions of the plugin from n/a through 3.6.7 are affected. Users of this plugin are advised to take immediate steps to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Timeline β Vertical and Horizontal timeline plugin <= 3.6.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved