CVE-2024-3107: Spectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the getblockdefaultattributes function. This allows authenticated attackers, with contributor-level permissions and above, to read the contents of any files named attributes.php on the server, which can contain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3107?
CVE-2024-3107 has a moderate severity level due to its potential impact on file security when exploited.
How do I fix CVE-2024-3107?
To fix CVE-2024-3107, update the Spectra – WordPress Gutenberg Blocks plugin to version 2.12.7 or higher.
Who is affected by CVE-2024-3107?
CVE-2024-3107 affects users of the Spectra – WordPress Gutenberg Blocks plugin versions up to and including 2.12.6.
What type of attack is CVE-2024-3107 associated with?
CVE-2024-3107 is associated with a Path Traversal attack that allows unauthorized file access.
What user roles are impacted by CVE-2024-3107?
Authenticated users with contributor-level permissions and above can exploit CVE-2024-3107.