Path traversal in WordPress - CVE-2024-6306
Published: June 25, 2024
Vulnerability identifier: #VU93316
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-6306
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
Note, the vulnerability affects files hosted on Windows only.
Affected software
WordPress
Fedora
wordpress
Fedora
wordpress
How to mitigate CVE-2024-6306
Install update from vendor's website.
WordPress - addressed in versions 4.1.41, 4.2.38, 4.3.34, 4.4.33, 4.5.32, 4.6.29, 4.7.29, 4.8.25, 4.9.26, 5.0.22, 5.1.19, 5.2.21, 5.3.18, 5.4.16, 5.5.15, 5.6.14, 5.7.12, 5.8.10, 5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5, 6.5.5
wordpress - addressed in versions 6.5.5-1.el9, 6.5.5-1.fc39, 6.5.5-1.fc40
wordpress - addressed in versions 6.5.5-1.el9, 6.5.5-1.fc39, 6.5.5-1.fc40