First published: Mon Apr 10 2023(Updated: )
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hummingbird | <3.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Hummingbird WordPress plugin is CVE-2023-1478.
The severity of CVE-2023-1478 is critical with a severity value of 9.8.
The Hummingbird WordPress plugin version before 3.4.2 is affected.
CVE-2023-1478 is a path traversal vulnerability in the page cache module of the Hummingbird WordPress plugin before 3.4.2, caused by the plugin not validating the generated file path for page cache files before writing them.
Yes, you can find more information about CVE-2023-1478 at this reference: https://wpscan.com/vulnerability/512a9ba4-01c0-4614-a991-efdc7fe51abe