CVE-2024-27954: WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27954?
CVE-2024-27954 is classified as a critical vulnerability due to its potential for arbitrary file downloads and server-side request forgery.
How do I fix CVE-2024-27954?
To fix CVE-2024-27954, update WP Automatic to version 3.92.1 or later immediately.
What versions of WP Automatic are affected by CVE-2024-27954?
CVE-2024-27954 affects all versions of WP Automatic from n/a through 3.92.0.
What type of vulnerability is CVE-2024-27954?
CVE-2024-27954 is a Path Traversal vulnerability that allows unauthorized access to files on the server.
Can CVE-2024-27954 lead to data breaches?
Yes, if exploited, CVE-2024-27954 can potentially lead to significant data breaches due to its server-side request forgery capabilities.