CVE-2024-31300: WordPress Easy Social Share Buttons plugin <= 9.4 - Local File Inclusion vulnerability
Published May 17, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.
Affected Software
2 affected components
Appscreo Easy Social Share Buttons>n/a, <=9.4
WordPress Easy Social Share Buttons<=9.4
Remediation
Information
Update to 9.5 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31300?
CVE-2024-31300 is rated as a high-severity vulnerability due to its potential for local file inclusion attacks.
2
How do I fix CVE-2024-31300?
To fix CVE-2024-31300, update Easy Social Share Buttons to version 9.5 or later to close the path traversal vulnerability.
3
What does CVE-2024-31300 affect?
CVE-2024-31300 affects Easy Social Share Buttons versions up to and including 9.4.
4
What type of vulnerability is CVE-2024-31300?
CVE-2024-31300 is classified as a path traversal vulnerability leading to local file inclusion.
5
Can CVE-2024-31300 allow unauthorized access to system files?
Yes, CVE-2024-31300 can potentially allow attackers to access and include unauthorized files on the server.