Remote File Inclusion Vulnerability in Spider Themes EazyDocs
CVE-2024-54376

7.5HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
16 December 2024

Summary

CVE-2024-54376 is a high-risk Remote File Inclusion (RFI) vulnerability present in the Spider Themes EazyDocs plugin. This vulnerability arises from improper control of the filename in include or require statements within the PHP application, which could allow an attacker to exploit this flaw by injecting malicious scripts into the server. This critical security issue specifically affects EazyDocs versions from n/a to 2.5.5, and if left unpatched, it could lead to unauthorized access, data breaches, or complete server compromise. Organizations using the affected versions are strongly advised to upgrade to the latest release and apply necessary security measures.

Affected Version(s)

EazyDocs <= 2.5.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kslatz (Patchstack Alliance)
.