CVE-2018-18576: Path Traversal
Published Mar 17, 2020
·Updated
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
Affected Software
1 affected component
Incsub Hustle Wordpress<=6.0.5
Event History
Mar 17, 2020
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Frequently Asked Questions
1
What is CVE-2018-18576?
CVE-2018-18576 is a vulnerability in The Hustle (aka wordpress-popup) plugin for WordPress that allows Directory Traversal to obtain a directory listing.
2
How severe is CVE-2018-18576?
CVE-2018-18576 has a severity rating of 5.3 (Medium).
3
What software versions are affected by CVE-2018-18576?
The Hustle (aka wordpress-popup) plugin versions up to and including 6.0.5 for WordPress are affected by CVE-2018-18576.
4
How can I fix CVE-2018-18576?
To fix CVE-2018-18576, it is recommended to update The Hustle (aka wordpress-popup) plugin to a version that is not vulnerable.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-18576?
The Common Weakness Enumeration (CWE) ID for CVE-2018-18576 is CWE-22.