CVE-2024-37513: WordPress WPCafe plugin <= 2.2.27 - Local File Inclusion vulnerability
Published Jul 9, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue affects WPCafe: from n/a through 2.2.27.
Affected Software
1 affected component
Themewinter Wpcafe Wordpress<2.2.28
Remediation
Information
Update to 2.2.28 or a higher version.
Event History
Jul 9, 2024
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37513?
CVE-2024-37513 has a medium severity rating due to its potential for path traversal attacks.
2
How do I fix CVE-2024-37513?
To fix CVE-2024-37513, update Themewinter WPCafe to version 2.2.28 or later.
3
What software versions are affected by CVE-2024-37513?
CVE-2024-37513 affects Themewinter WPCafe versions prior to 2.2.28.
4
What type of vulnerability is CVE-2024-37513?
CVE-2024-37513 is classified as a Path Traversal vulnerability.
5
Can CVE-2024-37513 lead to data leakage?
Yes, CVE-2024-37513 can potentially lead to unauthorized access to sensitive files on the server.