CVE-2024-43248: WordPress Bit Form Pro plugin <= 2.6.4 - Unauthenticated Arbitrary File Deletion vulnerability
Published Aug 19, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.
Affected Software
1 affected component
Bitapps Bit Form Wordpress<=2.6.4
Event History
Aug 19, 2024
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43248?
CVE-2024-43248 is classified as a high severity vulnerability due to its potential for unauthorized file manipulation.
2
How do I fix CVE-2024-43248?
To mitigate CVE-2024-43248, it is recommended to update Bit Form Pro to version 2.6.5 or later.
3
What does CVE-2024-43248 affect?
CVE-2024-43248 affects the Bit Form Pro plugin for WordPress versions up to and including 2.6.4.
4
Is CVE-2024-43248 a remote vulnerability?
CVE-2024-43248 allows unauthenticated users to exploit the vulnerability, indicating it is a remote vulnerability.
5
What type of vulnerability is CVE-2024-43248?
CVE-2024-43248 is a path traversal vulnerability that allows file manipulation within the affected system.