CVE-2024-38706: WordPress HT Mega plugin <= 2.5.7 - JSON Path Traversal vulnerability
Published Jul 12, 2024
·Updated
Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7.
Affected Software
3 affected components
HasThemes HT Mega>undefined
WordPress HT Mega Plugin<=2.5.7
HasThemes Ht Mega Wordpress<2.5.8
Remediation
Information
Update to 2.5.8 or a higher version.
Event History
Jul 12, 2024
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38706?
CVE-2024-38706 is classified as a high severity vulnerability due to its potential for path traversal attacks.
2
How do I fix CVE-2024-38706?
To fix CVE-2024-38706, update the HT Mega plugin to version 2.5.8 or later.
3
What systems are affected by CVE-2024-38706?
CVE-2024-38706 affects HasThemes HT Mega plugin versions prior to 2.5.8.
4
Can CVE-2024-38706 lead to unauthorized access?
Yes, CVE-2024-38706 can lead to unauthorized access to sensitive files on the server due to its path traversal nature.
5
Is there a workaround for CVE-2024-38706?
A temporary workaround for CVE-2024-38706 is to restrict file access to only necessary directories until the plugin is updated.