CVE-2024-12719: WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfuajaxactionreadsubfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform limited path traversal to view directories and subdirectories in WordPress. Files cannot be viewed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12719?
CVE-2024-12719 is considered to have a medium severity due to unauthorized access risks.
How do I fix CVE-2024-12719?
To fix CVE-2024-12719, update the WordPress File Upload plugin to version 4.24.16 or later.
Who is affected by CVE-2024-12719?
Authenticated users with subscriber-level permissions are affected by CVE-2024-12719.
What components are impacted by CVE-2024-12719?
CVE-2024-12719 impacts the 'wfu_ajax_action_read_subfolders' function in the WordPress File Upload plugin.
What types of attacks can exploit CVE-2024-12719?
CVE-2024-12719 allows authenticated attackers to access sensitive data without proper authorization.