CVE-2024-38768: WordPress The Pack Elementor addons plugin <= 2.0.8.6 - Local File Inclusion vulnerability
Published Aug 1, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local File Inclusion, Path Traversal.This issue affects The Pack Elementor addons: from n/a through 2.0.8.6.
Affected Software
3 affected components
webangon The Pack Elementor Addons Wordpress<2.0.8.7
webangon The Pack Elementor addons<=2.0.8.6
WordPress The Pack Elementor addons<=2.0.8.6
Remediation
Information
Update to 2.0.8.7 or a higher version.
Event History
Aug 1, 2024
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38768?
CVE-2024-38768 is a high severity vulnerability due to its ability to allow PHP Local File Inclusion, leading to potential exposure of sensitive files.
2
How do I fix CVE-2024-38768?
To fix CVE-2024-38768, upgrade The Pack Elementor addons to version 2.0.8.7 or later.
3
What type of vulnerability is CVE-2024-38768?
CVE-2024-38768 is classified as a Path Traversal vulnerability.
4
What versions are affected by CVE-2024-38768?
CVE-2024-38768 affects The Pack Elementor addons versions through 2.0.8.6 inclusive.
5
What are the consequences of CVE-2024-38768?
Exploitation of CVE-2024-38768 can lead to unauthorized access to sensitive files on the server.