CVE-2023-32297: WordPress LWS Affiliation plugin <= 2.2.6 - Local File Inclusion vulnerability
Published May 17, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.
Affected Software
2 affected components
LWS LWS Affiliation>=n/a<2.2.6
WordPress LWS Affiliation plugin<=2.2.6
Remediation
Information
Update to 2.3 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:44 AM
Data Sourced
via MITRE·06:44 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32297?
CVE-2023-32297 is classified as a medium severity vulnerability due to its potential for local file inclusion.
2
How do I fix CVE-2023-32297?
To fix CVE-2023-32297, update the LWS Affiliation plugin to version 2.2.7 or later.
3
What type of vulnerability is CVE-2023-32297?
CVE-2023-32297 is a 'Path Traversal' vulnerability that allows for PHP Local File Inclusion.
4
Which versions of LWS Affiliation are affected by CVE-2023-32297?
LWS Affiliation versions from n/a up to and including 2.2.6 are affected by CVE-2023-32297.
5
Is the LWS Affiliation plugin for WordPress affected by CVE-2023-32297?
Yes, the WordPress LWS Affiliation plugin up to version 2.2.6 is affected by CVE-2023-32297.