CVE-2024-10011: BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enables file uploads to directories outside of the web root. Depending on server configuration it may be possible to upload files with double extensions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10011?
CVE-2024-10011 is considered a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2024-10011?
To fix CVE-2024-10011, update the BuddyPress plugin to version 14.1.1 or higher.
Who is affected by CVE-2024-10011?
CVE-2024-10011 affects all versions of the BuddyPress plugin for WordPress up to and including 14.1.0.
What type of vulnerability is CVE-2024-10011?
CVE-2024-10011 is a Directory Traversal vulnerability that allows for accessing files outside the intended directory.
What actions can attackers perform exploiting CVE-2024-10011?
Authenticated attackers with Subscriber-level access and above can perform unauthorized actions on files due to CVE-2024-10011.