CVE-2024-43221: WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerability
Published Aug 19, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilder allows PHP Local File Inclusion.This issue affects JetGridBuilder: from n/a through 1.1.2.
Affected Software
2 affected components
Crocoblock JetGridBuilder>=n/a, <=1.1.2
WordPress JetGridBuilder<=1.1.2
Remediation
Information
Update to 1.1.3 or a higher version.
Event History
Aug 19, 2024
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43221?
CVE-2024-43221 is considered a high severity vulnerability due to its potential for PHP Local File Inclusion.
2
How do I fix CVE-2024-43221?
To fix CVE-2024-43221, upgrade the Crocoblock JetGridBuilder plugin to version 1.1.3 or later.
3
Which versions of JetGridBuilder are affected by CVE-2024-43221?
CVE-2024-43221 affects all versions of JetGridBuilder from n/a up to and including 1.1.2.
4
What type of vulnerability is CVE-2024-43221?
CVE-2024-43221 is a Path Traversal vulnerability that leads to PHP Local File Inclusion.
5
Who is responsible for addressing CVE-2024-43221?
The vendor Crocoblock is responsible for addressing CVE-2024-43221 and providing the necessary patches.