CVE-2024-32830: WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32830?
CVE-2024-32830 is classified as a high severity vulnerability due to its potential for server-side request forgery and path traversal exploitation.
How do I fix CVE-2024-32830?
To mitigate CVE-2024-32830, update the BuddyForms plugin to the latest version that addresses the vulnerability.
What types of attacks are possible with CVE-2024-32830?
CVE-2024-32830 allows for server-side request forgery and relative path traversal, which could enable unauthorized access to sensitive files or services.
Which versions of BuddyForms are affected by CVE-2024-32830?
CVE-2024-32830 affects BuddyForms versions from n/a up to and including 2.8.8.
Who is affected by CVE-2024-32830?
Users of the ThemeKraft BuddyForms plugin, specifically those using versions up to 2.8.8, are affected by CVE-2024-32830.