CVE-2023-37385: WordPress Consulting theme <= 6.5.6 - Local File Inclusion
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37385?
CVE-2023-37385 has a high severity rating due to the potential for PHP Local File Inclusion, allowing unauthorized access to sensitive files.
How do I fix CVE-2023-37385?
To fix CVE-2023-37385, update the StylemixThemes Consulting plugin to version 6.5.7 or later.
What versions of Consulting are affected by CVE-2023-37385?
CVE-2023-37385 affects versions of Consulting from n/a through 6.5.6.
What can an attacker do with CVE-2023-37385?
An attacker exploiting CVE-2023-37385 can perform PHP Local File Inclusion which may lead to the exposure of sensitive data or system compromise.
Is CVE-2023-37385 specific to a certain platform?
Yes, CVE-2023-37385 specifically impacts the StylemixThemes Consulting plugin used on WordPress websites.