CVE-2024-24869: WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerability
Published May 17, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.
Affected Software
3 affected components
BoldGrid Total Upkeep>=1.15.8
WordPress Total Upkeep<=1.15.8
BoldGrid Total Upkeep Wordpress<1.15.9
Remediation
Information
Update to 1.15.9 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24869?
CVE-2024-24869 is classified as a Path Traversal vulnerability, which can potentially lead to unauthorized file access.
2
How do I fix CVE-2024-24869?
To mitigate CVE-2024-24869, update BoldGrid Total Upkeep to version 1.15.9 or later.
3
Which versions of Total Upkeep are affected by CVE-2024-24869?
CVE-2024-24869 affects BoldGrid Total Upkeep versions from n/a through 1.15.8.
4
What kind of attack does CVE-2024-24869 enable?
CVE-2024-24869 allows for relative Path Traversal attacks that can lead to unauthorized file downloads.
5
Is CVE-2024-24869 a known vulnerability in WordPress plugins?
Yes, CVE-2024-24869 is a recognized vulnerability impacting the WordPress version of the Total Upkeep plugin.