CVE-2024-32729: WordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal.
This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Conversational Forms for ChatBotto a version that resolves this vulnerability.Fixed in 1.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32729?
The severity of CVE-2024-32729 is rated as high with a CVSS score of 7.5.
How do I fix CVE-2024-32729?
To fix CVE-2024-32729, upgrade the QuantumCloud Conversational Forms for ChatBot plugin to version 1.1.9 or later.
What type of vulnerability is CVE-2024-32729?
CVE-2024-32729 is a Path Traversal vulnerability that allows arbitrary file downloads.
Which versions of the QuantumCloud Conversational Forms plugin are affected by CVE-2024-32729?
CVE-2024-32729 affects the QuantumCloud Conversational Forms for ChatBot plugin from versions n/a through 1.1.8.
What risk does CVE-2024-32729 pose to users?
CVE-2024-32729 can potentially allow unauthorized access to sensitive files on the server, posing a significant security risk.