CVE-2024-13791: Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13791?
CVE-2024-13791 is considered a high severity vulnerability due to its potential for unauthorized file access by authenticated attackers with administrator-level access.
How do I fix CVE-2024-13791?
To fix CVE-2024-13791, update the Bit Assist plugin to the latest version beyond 1.5.2 or implement safeguards against path traversal attacks.
Who is affected by CVE-2024-13791?
All versions of the Bit Assist plugin for WordPress up to and including 1.5.2 are affected by CVE-2024-13791.
What types of attacks can CVE-2024-13791 facilitate?
CVE-2024-13791 can facilitate attacks that allow authenticated users to read arbitrary files on the server.
When was CVE-2024-13791 reported?
CVE-2024-13791 was reported in 2024, highlighting the vulnerability in the Bit Assist plugin's downloadResponseFile() function.