CVE-2024-37520: WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin <= 2.1.12 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 2.1.12.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37520?
The severity of CVE-2024-37520 has not been explicitly rated, but it involves a Path Traversal vulnerability which can lead to unauthorized file access.
How do I fix CVE-2024-37520?
To fix CVE-2024-37520, you should upgrade the RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons to version 2.1.13 or later.
What systems are affected by CVE-2024-37520?
CVE-2024-37520 affects the RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons from versions n/a through 2.1.12.
What is Path Traversal in the context of CVE-2024-37520?
Path Traversal in the context of CVE-2024-37520 refers to the vulnerability that allows an attacker to access files and directories outside the intended directory.
Is there a public exploit for CVE-2024-37520?
As of now, there is no public exploit available for CVE-2024-37520, but its existence poses a risk if the vulnerable version is still in use.