First published: Sat Jan 25 2025(Updated: )
The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via the 'file' attribute of the 'abcjs' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABC Notation plugin for WordPress | <=6.1.3 | |
Paulrosen Abc Notation Wordpress | <=6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13550 has been classified with a high severity level due to its potential to allow unauthorized access to sensitive files.
CVE-2024-13550 affects all users of the ABC Notation plugin for WordPress versions up to and including 6.1.3.
To fix CVE-2024-13550, update the ABC Notation plugin for WordPress to the latest version available that addresses this vulnerability.
CVE-2024-13550 represents a Path Traversal vulnerability that can be exploited by authenticated attackers.
Attackers need at least Contributor-level access or higher to exploit CVE-2024-13550.