CVE-2023-2252: Directorist < 7.5.4 - Admin+ LFI
Published Jan 16, 2024
·Updated
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
Affected Software
1 affected component
wpWax Directorist Wordpress<7.5.4
Event History
Jan 16, 2024
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2252?
CVE-2023-2252 is classified as a high severity vulnerability due to its potential for local file inclusion.
2
How do I fix CVE-2023-2252?
To fix CVE-2023-2252, update the Directorist plugin to version 7.5.4 or later.
3
What types of attacks can CVE-2023-2252 facilitate?
CVE-2023-2252 can facilitate local file inclusion attacks, allowing attackers to read sensitive files on the server.
4
Which versions of the Directorist plugin are affected by CVE-2023-2252?
Versions of the Directorist plugin prior to 7.5.4 are affected by CVE-2023-2252.
5
Is there a known exploit for CVE-2023-2252?
Yes, attacks exploiting CVE-2023-2252 leverage the vulnerability to gain unauthorized access to server files.