CVE-2024-13374: WP Table Manager <= 4.1.3 - Missing Authorization to Authenticated (Subscriber+) Directory Traversal to Folder/File Name Disclosure
The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptmgetFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary file names and directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13374?
CVE-2024-13374 is classified as a high severity vulnerability due to unauthorized access risks.
How do I fix CVE-2024-13374?
To fix CVE-2024-13374, upgrade the WP Table Manager plugin to version 4.1.4 or higher.
Who is impacted by CVE-2024-13374?
CVE-2024-13374 impacts authenticated users with Subscriber-level access and above using vulnerable versions of the WP Table Manager.
What is the nature of the vulnerability in CVE-2024-13374?
CVE-2024-13374 is due to a missing capability check that allows unauthorized access to the wptm_getFolders AJAX action.
In which versions of WP Table Manager does CVE-2024-13374 exist?
CVE-2024-13374 exists in all versions of WP Table Manager up to and including 4.1.3.