Full Path Disclosure in Glossary Plugin for WordPress
CVE-2024-6570

5.3MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
16 July 2024

What is CVE-2024-6570?

The Glossary plugin for WordPress, up to version 2.2.26, is susceptible to a Full Path Disclosure due to improper handling of file access and the enabling of display_errors. This exposure allows unauthenticated attackers to view the full path of the web application, potentially serving as a foothold for further exploitation. While the disclosed paths alone do not lead to immediate harm, they can inform other types of attacks if additional vulnerabilities are present.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.