CVE-2024-37410: WordPress PowerPack Lite for Beaver Builder plugin <= 1.3.0.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue affects PowerPack Lite for Beaver Builder: from n/a through <= 1.3.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37410?
CVE-2024-37410 is classified as a medium severity vulnerability due to its potential for path traversal exploits.
How do I fix CVE-2024-37410?
To fix CVE-2024-37410, update PowerPack Lite for Beaver Builder to version 1.3.0.4 or later.
Which versions of PowerPack Lite for Beaver Builder are affected by CVE-2024-37410?
CVE-2024-37410 affects all versions of PowerPack Lite for Beaver Builder up to and including 1.3.0.3.
What type of vulnerability is CVE-2024-37410?
CVE-2024-37410 is a path traversal vulnerability, which allows unauthorized access to files in the server's filesystem.
Who is impacted by CVE-2024-37410?
Users of the PowerPack Lite for Beaver Builder plugin on WordPress versions prior to 1.3.0.4 are impacted by CVE-2024-37410.