CVE-2024-43955: WordPress Droip plugin < 2.5.2 - Arbitrary File Deletion vulnerability
Published Aug 29, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip droip allows Path Traversal.This issue affects Droip: from n/a through < 2.5.2.
Affected Software
1 affected component
Themeum Droip Wordpress<=1.1.1
Event History
Aug 29, 2024
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43955?
CVE-2024-43955 has been assessed with a critical severity due to its potential for unauthorized file manipulation.
2
How do I fix CVE-2024-43955?
To fix CVE-2024-43955, update the Themeum Droip plugin to the latest version beyond 1.1.1, which addresses this vulnerability.
3
What is the impact of CVE-2024-43955?
The impact of CVE-2024-43955 allows attackers to perform arbitrary file downloads and deletions through path traversal.
4
Which versions of Droip are affected by CVE-2024-43955?
CVE-2024-43955 affects all versions of Droip up to and including version 1.1.1.
5
Is there a workaround for CVE-2024-43955?
Currently, there are no known workarounds for CVE-2024-43955, making it essential to apply the official update.