CVE-2024-11219: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the getimage function. This makes it possible for unauthenticated attackers to view arbitrary images on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11219?
The severity of CVE-2024-11219 is considered to be medium as it allows unauthenticated attackers to exploit the vulnerability via path traversal.
How do I fix CVE-2024-11219?
To fix CVE-2024-11219, update the Otter Blocks plugin to version 3.0.7 or later.
What is affected by CVE-2024-11219?
CVE-2024-11219 affects all versions of the Otter Blocks plugin for WordPress up to and including version 3.0.6.
What happens if CVE-2024-11219 is exploited?
If CVE-2024-11219 is exploited, it allows attackers to view arbitrary images on the server, potentially leading to information disclosure.
Who can exploit CVE-2024-11219?
CVE-2024-11219 can be exploited by unauthenticated attackers, meaning no login is required to carry out the attack.