CVE-2024-13613: Wise Chat <= 3.3.3 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file attachments included in chat messages. The vulnerability was partially patched in version 3.3.3.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13613?
CVE-2024-13613 is classified as a medium severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2024-13613?
To fix CVE-2024-13613, update the Wise Chat plugin to version 3.3.4 or later.
What kind of data is vulnerable in CVE-2024-13613?
CVE-2024-13613 allows attackers to access sensitive data stored insecurely in the '/wp-content/uploads' directory.
Who is affected by CVE-2024-13613?
CVE-2024-13613 affects all versions of the Wise Chat plugin for WordPress up to and including version 3.3.3.
Can unauthenticated attackers exploit CVE-2024-13613?
Yes, unauthenticated attackers can exploit CVE-2024-13613 to extract sensitive information.